Security

A response list can expose your priorities without holding the evidence.

Hostnames, owners, assessments, and next actions can be sensitive on their own. KnownScope treats the Campaign as governed security data even when packet captures, forensic images, and regulated evidence stay in another system.

Application controls

Permissions follow every way the record can be read or changed.

  1. Identity and sessions

    Human access uses OIDC with authorization code and PKCE. Sessions remain server-side, MFA policy stays with the identity provider, and the recovery administrator is a separate, tightly controlled path.

  2. Authorization and tenant isolation

    Access is denied unless a user or group has the required product and Campaign role. The API checks that role on every request, and database row-level policy enforces the tenant boundary.

  3. Change integrity

    Conflicting edits do not silently overwrite one another. Field changes, Work log revisions, access changes, duplicate decisions, imports, and published updates retain authorship and time.

  4. Safe data movement

    Imports are parsed in bounded staging, validated before commit, and recorded with their source. Exports, API responses, search, and webhooks apply the same Campaign permissions and field policies.

Production operations

The service has to protect the record after the code ships.

Production security includes recovery, observability, resource controls, and the path used to build and promote each release.

Encryption and secrets
Traffic is encrypted in transit, managed storage is encrypted at rest, and application secrets live in a managed secret store outside source code and image layers.
Least privilege and telemetry
Workloads use separate identities and narrow service permissions. Logs, metrics, and traces support investigation without recording secrets or Campaign content by default.
Recovery
Automated backups, point-in-time recovery, restore exercises, and documented runbooks support the recovery targets named in the service agreement.
Software supply chain
Locked dependencies, static analysis, secret scanning, dependency and image scanning, an SBOM, and controlled artifact promotion are part of the build and release path.
Abuse and resource limits
Rate limits, quotas, file-size limits, timeouts, and bounded Data Source execution keep one user, import, or integration from exhausting shared resources.

Independent assurance

Claims follow evidence.

There is no certification, independent assessment, or penetration-test report to show you today. When one exists, this page will name it with its scope and its date. If that is a blocker for your organization, it should block us now rather than after four meetings.

On data residency the answer is simpler than usual: during the private preview KnownScope runs on your infrastructure, against your own PostgreSQL, in whichever region you already operate. Nothing leaves it.

Security contact

Report a suspected security issue.

Send a short description, the affected page or service, the impact you observed, and a safe way to reproduce it. The website terms do not create a safe-harbor or response-time commitment.

Next step

Bring the security questions that affect approval.

Send the identity, data handling, recovery, assurance, and integration requirements your reviewers use. We will map them to the product and service terms.