Trust center
Security product. Security posture.
Explicit authorization, least privilege, redaction and hardened runtime boundaries.
Authorized scanning
Target verification is required before red-team testing; private and reserved network targets are rejected to reduce SSRF risk.
Hardened service
The production container runs read-only, drops Linux capabilities, uses no-new-privileges and is exposed only through the reverse proxy.
Session protection
HTTP-only sessions, strict SameSite behavior, secure HTTPS cookies and CSRF checks protect state-changing portal actions.
Secret handling
Security analysis includes secret-pattern detection and redaction before downstream use.
Evidence & audit
Findings, policy decisions and scan reports provide reproducible remediation evidence.
Controlled enforcement
Monitoring is separated from blocking; high-impact actions can require approval or quarantine.