Access controls
Local accounts support TOTP multi-factor authentication and single-use recovery codes. Generic OpenID Connect supports compatible identity providers, group-to-role mapping and domain restrictions. Roles separate administration, security engineering, viewing and audit access.
Data handling
Connector credentials are encrypted at rest. Sessions use server-side state, secure cookies and CSRF protection. The customer-hosted deployment keeps raw security events in the customer environment.
Network and runtime
The Helm deployment uses non-root containers, a read-only root filesystem, dropped Linux capabilities and Kubernetes NetworkPolicies. Audit actions are recorded without secret values.
Report a vulnerability
Send security reports to hello@cybermeasures.io. Include the affected component, impact and reproduction details. We will acknowledge valid reports and coordinate remediation.