Security disclosure · Not launch-ready

Security

Security pages are useful only when they tell the truth. This one does: the product has significant hardening work already, but the public disclosure operation is not staffed or launched from this branch.

Public disclosure status

Unpublished inbox

No monitored public security address is configured in this build, so this page does not claim an active intake channel.

True blockers

Operations still required

MFA, least privilege, secret rotation, monitored reporting, incident playbooks, and zero open critical/high findings remain required before launch claims.

What this page can state honestly today

  • No public bug bounty, PGP key, or monitored disclosure inbox is claimed by this credential-free scaffold.
  • Do not send secrets, provider credentials, payment details, or private customer data through an unpublished support path.
  • Independent security review, incident drills, release revocation, and monitored disclosure operations remain pre-launch requirements.

The customer platform plan also requires cross-account review, CSRF/XSS/CSP abuse testing, release-revocation drills, and an independent security review before the security program can be described as ready.

Disclosure intake placeholder

This placeholder proves the site does not fake a disclosure intake. A monitored security mailbox, triage process, and acknowledgement workflow are still operator work items.

Security report placeholder

This form fails closed in the credential-free build. No message leaves the browser because no monitored inbox or ticket processor is configured here yet.