Trust center / Evidence
Security is a maintained control system, not a badge.
Kedabek publishes architecture, threat boundaries, control objectives, test dates, limitations, corrections, and a vulnerability channel without exposing customers or exploitable operations.
No certification claims01
Implemented in this release
- User-agent-independent public responses
- Public edge denial for every operations API path
- Forged identity headers cannot reach the application or database
- Tenant-scoped authorization and approval policy retained as an unreleased reference implementation
- No shell, arbitrary payload, deployment executor, credential, or public-provisioning endpoint
- Content-security, anti-framing, MIME, privacy, and no-store headers
- Dependency audit and source-level policy tests
02
Required before execution
- Scoped service identities and customer-owned credentials
- Secret scanning and protected release workflow
- SBOM, provenance, signed release receipt, and tested rollback
- Tenant-isolation and authorization integration tests
- Incident runbook and restoration exercise
- Independent connector security review
03
Private boundaries
- No public lab access
- No user-agent-based authorization
- No customer secrets in source
- No raw leads or personal queries in public evidence
- No unpatched exploit detail
- No hidden persistent support channel
04
Accurate promise
Controls are designed to reduce identified risk. Kedabek does not promise perfect security, automatic legal compliance, immunity from claims, or a substitute for qualified counsel.
- Public vulnerability contact
- Documented correction process
- Incident-specific retention exception
- Customer approval for consequential changes
Next mission
Report a vulnerability
Use the published security contact and include enough detail for safe reproduction.