Security
This page states what this build actually does. It is not a penetration-test report.
- The public site is served over HTTPS.
- The interactive sample is one shared database, not a separate tenant per customer. Do not put real vendor certificates in the public sample.
- The data model has a role column (owner, admin, reviewer, field, AP, read-only). The sample signs in as one owner. Those roles are not enforced in the app.
- Gate overrides in the sample write an audit row with actor, reason, and time.
- Agent keys are stored hashed. The sample key is for that shared shop.
- SSO is not built. SOC 2 is not certified. There is no report to send.
- Report a security issue to support@coiops.com.