Workspace routes
Authentication and tenant context apply before product records are read or changed.
Security
Review account access, tenant boundaries, authenticated routes, public forms, logs, edge protection, backups, incident handling, and the exact deployment configuration.
Control families
A control description should identify the protected surface and avoid implying that optional settings are enabled everywhere.
| Control family | Current posture | Purpose |
|---|---|---|
| Authorization | Tenant-aware data access, authenticated API routes, role and section controls, admin workflows | Restrict workspace records and administrative actions. |
| Authentication | Password login, supported organizational OAuth paths, MFA, backup codes, sessions, and revocation | Protect account access and provide recovery paths. |
| Request protection | CSRF controls, validation, honeypot fields, public endpoint checks, and rate limits | Reduce session abuse and automated public-form misuse. |
| Edge protection | HTTPS, HSTS, hardened headers, Nginx controls, firewalling, and CrowdSec | Reduce transport, browser, scanning, and commodity abuse risk. |
| Audit and response | Login events, activity records, security logs, alerting paths, and responsible disclosure | Support review, investigation, containment, and corrective action. |
Application security
Workspace data requires authenticated tenant-aware routes. Public contact, consent, privacy, and health paths require narrow validation and abuse controls.
Authentication and tenant context apply before product records are read or changed.
Validation, honeypot fields, rate limits, and configured bot checks reduce automated misuse.
MFA, backup codes, session review, revocation, and login records support account control.
Infrastructure and operations
The public deployment uses Nginx, TLS, security headers, firewall controls, CrowdSec, service isolation, monitoring, and backups. Procurement should confirm recovery and retention requirements for the intended deployment.
HTTPS, HSTS, certificates, hardened headers, firewalling, and scanner controls protect the public edge.
Application services use restricted accounts, local bindings, and system service controls.
Backups, integrity checks, logs, alerts, containment, communication, and corrective action belong in operating review.
Responsible disclosure
Email security@commandix.io with the affected URL, reproduction steps, impact, and safe proof. Avoid destructive testing, persistence, social engineering, and access to data that is not yours.
Use security@commandix.io for vulnerability reports and coordinated review.
The public security.txt file provides the current contact and policy metadata.
Open security.txtSend the control questions, intended data, identity requirements, enabled connections, regions, and recovery expectations.