Required MFA
Password and authenticator sign-in, PKCE and exact callbacks. Development local-password login is disabled.
Explore the controls configured in the hosted pilot and the validation still needed for a wider release.

These describe observed configuration, not a third-party certification.
Password and authenticator sign-in, PKCE and exact callbacks. Development local-password login is disabled.
Named operators, tenant/organisation role boundaries and forced row-level database security.
Public HTTPS and endpoint TLS 1.3. Agent identity uses installation certificates, separate from public server trust.
Group changes and access decisions enter the audit workflow. Independent external anchoring remains a release gate.
Encrypted, authenticated backups with an isolated database-and-key restore check. Full replacement-host recovery is still pending.
Provider deployment and endpoint acceptance remain distinct from control-plane health.
The product is not advertised as ISO 27001, SOC 2, FIPS or maritime-class certified. Independent assessment, release signing, load/soak testing and complete remote/SOC acceptance are pending.
HTTPS console, password + authenticator sign-in, scoped roles, groups and audit records.
Windows and Mac operator downloads. Remote session and production endpoint acceptance are still in progress.
Lab telemetry and findings. Production SOC infrastructure and monitoring acceptance remain pending.
Contact the project owner with a brief description. Do not send exploit secrets or private customer data through the public form.
Start with a conversation about your fleet, your workflows, and a controlled pilot.