Security

Security

Current security, tenant-isolation, source-storage and response-governance controls in the Sefixa hosted private pilot.

No certification claim. The controls below describe the current hosted Sefixa private pilot. They are internally tested product controls, not a claim of SOC 2, ISO 27001 or other independent certification.
Application security

Private source material stays behind authenticated workspace boundaries.

Workspace isolation

Projects, evidence, responses and exports are scoped to authenticated workspace membership, with database row-level policies as an additional boundary.

Private source access

Retained original evidence is stored privately and downloaded through authenticated no-store application paths rather than public source URLs.

Session controls

Hosted sessions use rotating HttpOnly cookies, provider-side validation and recovery behavior for stale or invalid credentials.

Audit history

Key uploads, project actions, review decisions, exports and retention changes are recorded for workspace governance.

Abuse protection

Persistent rate limiting, request identifiers, structured runtime logging and security headers support production operation.

Enterprise identity paths

SAML SSO mapping and SCIM provisioning paths exist; actual availability depends on configured identity-provider and underlying platform support.

Response safety is part of security.

Sefixa can require review for unsupported or stale-evidence responses and can block exports that do not meet configured approval conditions.