[ security ]
Defense without surveillance.
The controls below are stated as facts about the system, not marketing. No third-party certification is claimed; when one exists, it will be listed here.
data_boundary
Data and privacy boundary
Content-blind collection, app-scoped identifiers, bounded raw-batch derivation, and plan-bound retention.
- —No prompts, generated output, typed content, pointer coordinates, payment data, or raw IPs in customer telemetry.
- —Account and device references are re-hashed per app.
- —Enterprise customer history is retained for 90 days.
access
Identity and access
SAML/OIDC SSO, SCIM lifecycle enforcement, organization roles, and redacted immutable audit history.
- —SSO providers are exact-domain and organization bound.
- —SCIM deactivation removes organization access immediately.
- —Owner-only permissions cannot be delegated through custom roles.
delivery
Application and delivery security
One reviewed image, additive migrations, dependency scanning, health-gated rollout, and automatic rollback.
- —All production deployments promote immutable GHCR digests.
- —Failed health attestations restore the prior digest.
- —Enterprise capacity uses shared code and automated regional provisioning, never a customer fork.
resilience
Resilience and incident response
Durable backups, restore exercises, bounded workers, public service status, and explicit incident reporting.
- —Database-aware health checks gate deployment.
- —SLA reports disclose missing observation coverage.
- —Security reports must exclude credentials, request bodies, evidence, and customer data.
download_controls.json ↓materials version 2026-07-23 · no third-party certification claimed
security incidents: dan@ochoa.pro
Never send passwords, API keys, session tokens, evidence, request bodies, or customer data.