Published security profile
- • Permission-scoped integrations
- • Auditability where supported
- • Change and deployment controls
These items describe the intended or evidenced baseline relevant to this company. They do not imply that every technical control is implemented identically across every system. Repository- or service-specific controls are only treated as operating where the relevant implementation and evidence exist.
Evidence and assurance
Security claims are evidence-led. Automated assurance, dependency audits, secret-exposure checks, SBOM generation, linting, type checking, tests, SAST/CodeQL, build verification and deployment verification are not claimed for this company unless the relevant project actually implements them.
Planned certifications, independent testing and future controls remain described as planned until completed. Detailed evidence may contain sensitive architecture, supplier, account or vulnerability information and is shared only where appropriate for legitimate due diligence.