[ security ]

Defense without surveillance.

The controls below are stated as facts about the system, not marketing. No third-party certification is claimed; when one exists, it will be listed here.

data_boundary

Data and privacy boundary

Content-blind collection, app-scoped identifiers, bounded raw-batch derivation, and plan-bound retention.

  • No prompts, generated output, typed content, pointer coordinates, payment data, or raw IPs in customer telemetry.
  • Account and device references are re-hashed per app.
  • Enterprise customer history is retained for 90 days.
access

Identity and access

SAML/OIDC SSO, SCIM lifecycle enforcement, organization roles, and redacted immutable audit history.

  • SSO providers are exact-domain and organization bound.
  • SCIM deactivation removes organization access immediately.
  • Owner-only permissions cannot be delegated through custom roles.
delivery

Application and delivery security

One reviewed image, additive migrations, dependency scanning, health-gated rollout, and automatic rollback.

  • All production deployments promote immutable GHCR digests.
  • Failed health attestations restore the prior digest.
  • Enterprise capacity uses shared code and automated regional provisioning, never a customer fork.
resilience

Resilience and incident response

Durable backups, restore exercises, bounded workers, public service status, and explicit incident reporting.

  • Database-aware health checks gate deployment.
  • SLA reports disclose missing observation coverage.
  • Security reports must exclude credentials, request bodies, evidence, and customer data.
download_controls.json ↓materials version 2026-07-23 · no third-party certification claimed
security incidents: dan@ochoa.pro

Never send passwords, API keys, session tokens, evidence, request bodies, or customer data.