Draft pending owner and legal-counsel approvalNot yet effective
Security practices
A cautious technical description of implemented controls, not a security certificate or penetration-test report.
This is a technically complete surface for approved content, but the current text is an operational draft, not legal advice. Do not use it for public paid sales until entity details are completed and formally approved.
01
Product controls
- Organisation isolation, RLS and server-owned sensitive mutations.
- SSRF controls on scan URLs, browser request interception and runtime bounds.
- Private evidence and authorised download routes without intended public storage.
- Signed, replay-safe external events when providers are enabled.
- Audit records for sensitive administrative actions.
02
Claim boundary
These controls still require staging and production verification, external monitoring and tested backups. This page is not an ISO or SOC 2 claim, a penetration test, or a guarantee of vulnerability-free software.
03
Reporting
The owner must configure a private security disclosure channel before production. Do not send sensitive exploit details in an ordinary support form.