Trust center / Evidence

Security is a maintained control system, not a badge.

Kedabek publishes architecture, threat boundaries, control objectives, test dates, limitations, corrections, and a vulnerability channel without exposing customers or exploitable operations.

No certification claims
01

Implemented in this release

  • User-agent-independent public responses
  • Public edge denial for every operations API path
  • Forged identity headers cannot reach the application or database
  • Tenant-scoped authorization and approval policy retained as an unreleased reference implementation
  • No shell, arbitrary payload, deployment executor, credential, or public-provisioning endpoint
  • Content-security, anti-framing, MIME, privacy, and no-store headers
  • Dependency audit and source-level policy tests
02

Required before execution

  • Scoped service identities and customer-owned credentials
  • Secret scanning and protected release workflow
  • SBOM, provenance, signed release receipt, and tested rollback
  • Tenant-isolation and authorization integration tests
  • Incident runbook and restoration exercise
  • Independent connector security review
03

Private boundaries

  • No public lab access
  • No user-agent-based authorization
  • No customer secrets in source
  • No raw leads or personal queries in public evidence
  • No unpatched exploit detail
  • No hidden persistent support channel
04

Accurate promise

Controls are designed to reduce identified risk. Kedabek does not promise perfect security, automatic legal compliance, immunity from claims, or a substitute for qualified counsel.

  • Public vulnerability contact
  • Documented correction process
  • Incident-specific retention exception
  • Customer approval for consequential changes

Next mission

Report a vulnerability

Use the published security contact and include enough detail for safe reproduction.

Security contact