Home · Privacy · Support

Security

Report suspected vulnerabilities or tenant-boundary issues to security@ironhand.org. Include the affected URL, reproducible steps, impact, and a safe contact method. Do not access data that is not yours, disrupt emergency operations, create false alarms, or use destructive tests.

What to expect

We will acknowledge actionable reports, assess severity, preserve relevant evidence, and coordinate remediation and disclosure. Please allow a reasonable remediation period before public disclosure.

Current safeguards

The platform uses server-side tenant authorization, minimized public data, protected emergency actions, HTTPS enforcement, MFA for privileged changes, hashed credentials and tokens, encrypted integration secrets, upload and outbound-request validation, append-only audit events, dependency scanning, and health/worker monitoring. These controls still require independent penetration testing before unrestricted production launch.

Machine-readable policy: security.txt.