Trust Center

Security Practices

Organization APIs verify account identity and organization roles. The control plane publishes Ed25519-signed policies, and enrolled desktops verify every bundle against a pinned public key before applying it. Organization administration and signed policy authoring are available today; managed client enrollment and policy delivery are in development. SSO (Entra ID and generic OIDC/SAML) and SCIM user/group provisioning are implemented and enabled per deployment, with live identity-provider validation completed during onboarding.

Administrator step-up through Entra Conditional Access is supported. Instant device revocation while a device is offline and full SCIM profile coverage remain in development; revocation otherwise takes effect on the device's next policy check.

Full practices, including penetration test summaries where available, are published here only after the underlying artifacts exist and their scope and dates are reviewed.