Security Measures

Revised · policies/SECURITY-MEASURES.md ↗ · 0fa48e326878 ↗

These are the technical measures behind our DPA (Annex II). The organisational ones, from staff access to incident response, are our Corporate Policies. Our architecture shows where data flows.

Minimisation

  • IP addresses and user agents stop at Cloudflare's edge, unlogged.
  • Scan servers see only the artifact asked about, never who asked.
  • Usage records hold an org ID and counts, never the artifact.

Encryption and Isolation

  • Every connection uses TLS, authenticated as our trust boundaries describe.
  • Customer data is encrypted at rest. Our providers hold the keys.
  • Artifact analysis runs in disposable VMs with no path to production or customer data.

Access

  • Sessions end 48 hours after sign-in, and every action rechecks membership.
  • API tokens carry 130 random bits, at most four per org. Revocation takes effect within 60 seconds.

Availability

Four US regions each answer on their own. Without colo 1, the others grade with OpenRouter or answer without the LLM's second opinion. Scan servers fail over to a database replica. Backups: Business Continuity.

We review these measures yearly with our Risk Assessment.