Security

Security controls should match the operating data being protected.

Review account access, tenant boundaries, authenticated routes, public forms, logs, edge protection, backups, incident handling, and the exact deployment configuration.

Control families

Inspect what is implemented and what must be configured.

A control description should identify the protected surface and avoid implying that optional settings are enabled everywhere.

Control familyCurrent posturePurpose
AuthorizationTenant-aware data access, authenticated API routes, role and section controls, admin workflowsRestrict workspace records and administrative actions.
AuthenticationPassword login, supported organizational OAuth paths, MFA, backup codes, sessions, and revocationProtect account access and provide recovery paths.
Request protectionCSRF controls, validation, honeypot fields, public endpoint checks, and rate limitsReduce session abuse and automated public-form misuse.
Edge protectionHTTPS, HSTS, hardened headers, Nginx controls, firewalling, and CrowdSecReduce transport, browser, scanning, and commodity abuse risk.
Audit and responseLogin events, activity records, security logs, alerting paths, and responsible disclosureSupport review, investigation, containment, and corrective action.

Application security

Public and authenticated routes have different trust boundaries.

Workspace data requires authenticated tenant-aware routes. Public contact, consent, privacy, and health paths require narrow validation and abuse controls.

Workspace routes

Authentication and tenant context apply before product records are read or changed.

Public forms

Validation, honeypot fields, rate limits, and configured bot checks reduce automated misuse.

Sessions and account security

MFA, backup codes, session review, revocation, and login records support account control.

Infrastructure and operations

Security continues after the request reaches the server.

The public deployment uses Nginx, TLS, security headers, firewall controls, CrowdSec, service isolation, monitoring, and backups. Procurement should confirm recovery and retention requirements for the intended deployment.

Transport and edge

HTTPS, HSTS, certificates, hardened headers, firewalling, and scanner controls protect the public edge.

Service boundaries

Application services use restricted accounts, local bindings, and system service controls.

Recovery and response

Backups, integrity checks, logs, alerts, containment, communication, and corrective action belong in operating review.

Responsible disclosure

Send enough evidence for safe triage.

Email security@commandix.io with the affected URL, reproduction steps, impact, and safe proof. Avoid destructive testing, persistence, social engineering, and access to data that is not yours.

Disclosure contact

Use security@commandix.io for vulnerability reports and coordinated review.

Machine-readable route

The public security.txt file provides the current contact and policy metadata.

Open security.txt

Have a questionnaire or deployment requirement?

Send the control questions, intended data, identity requirements, enabled connections, regions, and recovery expectations.

Start security review