Security

Designed to operate inside the customer boundary.

CyberMeasures minimizes data movement and uses read-only collection wherever the workflow permits.

Access controls

Local accounts support TOTP multi-factor authentication and single-use recovery codes. Generic OpenID Connect supports compatible identity providers, group-to-role mapping and domain restrictions. Roles separate administration, security engineering, viewing and audit access.

Data handling

Connector credentials are encrypted at rest. Sessions use server-side state, secure cookies and CSRF protection. The customer-hosted deployment keeps raw security events in the customer environment.

Network and runtime

The Helm deployment uses non-root containers, a read-only root filesystem, dropped Linux capabilities and Kubernetes NetworkPolicies. Audit actions are recorded without secret values.

Report a vulnerability

Send security reports to hello@cybermeasures.io. Include the affected component, impact and reproduction details. We will acknowledge valid reports and coordinate remediation.