Trust Center

Bezpečnosť bez marketingových skratiek

Čo je implementované v produkte, čo závisí od deploymentu a čo ešte čaká na nezávislé overenie.

Control posture

Technické a assurance kontroly

release 3.7.0-rc29

Tenant isolation

Workspace-scoped authorization is enforced server-side and covered by automated tenant-isolation tests.

Implementované

Authentication & MFA

Password authentication, MFA and step-up authentication protect sensitive operations.

Implementované

Audit integrity

Security-relevant workspace changes are recorded in a chained HMAC-SHA256 audit log.

Implementované

Secrets & integration credentials

API/SCIM tokens are stored as digests and external integration credentials are encrypted before database storage.

Implementované

Malware scanning

Uploaded evidence can be scanned through ClamAV; production deployments can require successful scanning.

Podľa deploymentu

SSO / provisioning

Workspace-scoped OIDC SSO and SCIM 2.0 provisioning are available for enterprise deployments.

Implementované

Independent penetration test

The product includes a pentest readiness package, but no independent certification or pentest result is claimed here until evidence is published.

Čaká na nezávislé overenie
Čo tu zámerne netvrdíme

WOV Evidence na tejto stránke netvrdí SOC 2, ISO 27001 certifikáciu ani úspešný nezávislý pentest, kým k takému tvrdeniu neexistuje publikovateľný dôkaz.

DisclosureBezpečnostné hlásenia

Aktuálny bezpečnostný kontakt a disclosure policy sú publikované cez štandardný security.txt endpoint.

Otvoriť security.txt →
Data handlingTenant-scoped dáta

Workspace autorizácia, audit trail, evidence approvals a šifrované integračné credentials sú súčasťou aplikačného modelu.

Ochrana údajov →
AssurancePentest-ready

Release obsahuje scope/ROE balík pre externého testera a go-live checklist pre pilotné nasadenie.