Tenant isolation
Workspace-scoped authorization is enforced server-side and covered by automated tenant-isolation tests.
Čo je implementované v produkte, čo závisí od deploymentu a čo ešte čaká na nezávislé overenie.
Workspace-scoped authorization is enforced server-side and covered by automated tenant-isolation tests.
Password authentication, MFA and step-up authentication protect sensitive operations.
Security-relevant workspace changes are recorded in a chained HMAC-SHA256 audit log.
API/SCIM tokens are stored as digests and external integration credentials are encrypted before database storage.
Uploaded evidence can be scanned through ClamAV; production deployments can require successful scanning.
Workspace-scoped OIDC SSO and SCIM 2.0 provisioning are available for enterprise deployments.
The product includes a pentest readiness package, but no independent certification or pentest result is claimed here until evidence is published.
WOV Evidence na tejto stránke netvrdí SOC 2, ISO 27001 certifikáciu ani úspešný nezávislý pentest, kým k takému tvrdeniu neexistuje publikovateľný dôkaz.
Aktuálny bezpečnostný kontakt a disclosure policy sú publikované cez štandardný security.txt endpoint.
Otvoriť security.txt →Workspace autorizácia, audit trail, evidence approvals a šifrované integračné credentials sú súčasťou aplikačného modelu.
Ochrana údajov →Release obsahuje scope/ROE balík pre externého testera a go-live checklist pre pilotné nasadenie.