Digital Trust by Design
Enterprise-grade security, privacy, and responsible AI practices across all DefenAi Labs platforms.
Governance & security controls
Machine-readable control registry mapped to code evidence. Full list via /api/governance/controls.
Content Security Policy with nonces
Production script-src uses nonce + strict-dynamic without unsafe-inline/unsafe-eval.
Security response headers
X-Frame-Options, nosniff, Referrer-Policy, Permissions-Policy, COOP/CORP, optional HSTS.
Admin authentication & session hardening
HttpOnly SameSite cookies, hashed session tokens, rate-limited local login, optional Entra SSO.
OTP verification for gated flows
Peppered HMAC OTP hashes, TTL, attempt caps for brochure/TCO/contact/demo.
Upload content-type controls
Raster images only for content uploads; PDF magic-byte validation for brochures; SVG user uploads blocked.
Secrets encryption at rest
AES-256-GCM envelope for DB-stored credentials (LLM, Entra, email). KEK from SECRETS_ENCRYPTION_KEY or local data/secrets/platform-kek.
ISO Certifications
ISO 27001, ISO 42001 alignment
Security Policy
WAF, DDoS, CSP, MFA, DevSecOps
Privacy Policy
Data protection and DPDP compliance
Cookie Policy
Cookies, consent, and analytics
Terms & Conditions
Website and service terms of use
Responsible AI
AI ethics and human oversight
Vulnerability Disclosure
Report security vulnerabilities