Counsel-reviewable engineering draft
Security Overview and Responsible Disclosure Draft
Engineering security overview and a truthful disclosure-channel launch gate.
Security architecture
- SaaS, Portal customer, legacy Portal owner, local runtime, and platform-operator identities remain separate even when email addresses match.
- Tenant isolation, least-privilege roles, action-bound passkey step-up, revision fences, idempotency, signed release artifacts, signed entitlements, and sanitized audit are release gates.
- Self-hosted customer content and local member directories do not flow into the commercial Portal.
- Air-gapped operation has no runtime egress requirement.
Responsible disclosure status
A confidential production vulnerability-reporting channel, encryption key, response target, safe-harbor statement, and bug-bounty policy have not yet been approved. Do not place exploit details, secrets, personal data, or active credentials in a public issue.
Commercial launch remains blocked until a monitored private channel and response procedure are published. General non-sensitive engineering defects may continue to use the public repository issue tracker.