Security
Security treated as an operating requirement, not a feature list.
Our platforms are deployed in financial, government and high-volume commercial environments. Controls are applied across transport, application, identity, data and operational layers, and configured to each client's policy.
Control domains
Applied across every deployment
Transport and headers
- HTTPS enforcement
- HSTS
- Content Security Policy
- Secure response headers
Application controls
- CSRF protection
- XSS protection
- SQL-injection protection
- Strong input validation
- Output encoding
Identity and access
- Secure authentication
- Multi-factor authentication for administrators
- Role-based access control
- Session expiration
- Login-attempt monitoring and lockout controls
- Secure password hashing
Abuse prevention
- Rate limiting
- Bot and spam protection
- Anomaly monitoring
- Maker-checker controls where configured
Data protection
- Encrypted storage where appropriate
- Secure backups
- Data-retention controls
- Privacy-consent logging
- Data-residency options per deployment
Files and uploads
- File-upload validation
- File-type and size restrictions
- Malware scanning for uploaded files
- Isolated storage of submitted documents
Auditability
- Append-only audit logs where appropriate
- Admin activity history
- Security event logging
- Exportable audit trails
Disclosure
Reporting a security issue
If you believe you have identified a vulnerability in a NoDust.ai property or a deployed platform, contact our enterprise team with the affected asset, reproduction steps and impact assessment. We acknowledge reports and coordinate remediation with the affected client where a deployment is involved.
Security posture, certifications and contractual assurances are agreed per engagement. Deployment-specific documentation is provided under NDA during procurement.