Security disclosure · Not launch-ready

Security

The product has significant hardening work already, but no monitored public disclosure operation is configured for this beta. Do not send secrets, provider credentials, payment details, or private customer data through this unpublished path.

Public disclosure status

No monitored inbox

No monitored public security address is configured in this build, so this page does not claim an active intake channel.

True blockers

Operations still required

MFA, least privilege, secret rotation, monitored reporting, incident playbooks, and zero open critical/high findings remain required before launch claims.

What this page can state honestly today

  • No public bug bounty, PGP key, or monitored disclosure inbox is claimed by this credential-free scaffold.
  • Do not send secrets, provider credentials, payment details, or private customer data through an unpublished support path.
  • Independent security review, incident drills, release revocation, and monitored disclosure operations remain pre-launch requirements.

The customer platform plan also requires cross-account review, CSRF/XSS/CSP abuse testing, release-revocation drills, and an independent security review before the security program can be described as ready.

Disclosure intake unavailable

No monitored security mailbox is configured for this beta. The disclosure intake stays disabled until triage, acknowledgement, and escalation workflows are ready.

Security intake disabled

No message is sent. This intake remains disabled until a monitored inbox and processing path are configured.