Skip to main content
Menu

Security and compliance

Security is built into every layer of the platform, from identity to the software supply chain. These are the measures in place across our consoles and services.

Security measures

Identity and access

  • Dedicated customer identity provider
  • Passwords of 12 to 128 characters, password history and brute-force protection
  • TOTP and WebAuthn two-factor authentication
  • Role checks on every session

Sessions and exchanges

  • Server-side sessions, with no token exposed in the browser
  • Sessions limited to 8 hours and closed after 30 minutes of inactivity
  • Origin checks and anti-CSRF tokens on every change
  • Per-session rate limiting

Logging and audit

  • An audit event for every action
  • Standardised errors (RFC 9457), with no internal identifier exposed
  • Metrics and logs for every service

Software supply chain

  • Dependencies served from our sovereign forge, licences checked before adoption
  • Images pinned by digest, no floating tags in production
  • Unprivileged containers with a read-only file system

Data sovereignty

  • Data hosted in the region of your choice
  • Reversibility of data and configurations
  • No audience measurement tools or third-party resources, in our consoles or on this site

Certifications and vulnerability reporting

Certifications

No certification is claimed to date. Each certification obtained will be published here with its framework, scope, certification body and date.

Report a vulnerability

Contact us through the group contact form with “Security” as the subject. This site’s security.txt file lists the same channel.

Report a vulnerability

Contact us through the group contact form with “Security” as the subject. This site’s security.txt file lists the same channel.