TRUST / CONTROL MAP
Security and trust
Current application controls, production launch gates, data boundaries, and a responsible reporting route.
Build-stage control statement. Hosting certifications, penetration-test evidence, recovery objectives, and subprocessor attestations remain production launch gates.
Implemented application controls
- Organization-scoped authorization with explicit admin, analyst, and viewer capabilities.
- Durable idempotency keys, canonical input hashing, state-machine transition guards, validation boundaries, request throttling, and escaped JSON responses.
- Read-only public previews and first-release connector designs, with no automatic marketplace or provider mutations.
- Structured audit and incident packages from the shared infrastructure library, plus automated unit, feature, contract, property, accessibility, browser, security, and mutation gates.
Production launch gates
- Managed hosting with encryption in transit and at rest, isolated secrets, least-privilege runtime roles, backups, restore tests, patching, and alerting.
- OAuth review per platform, signed webhook validation, credential rotation, data-retention jobs, uninstall handling, and tenant-bound connector tokens.
- Independent security review, dependency and container scanning, incident exercises, recovery-objective validation, and a published subprocessor list.
Report a vulnerability
Use the support form, choose “Security report,” or email security@netlabs.app. Avoid including secrets or personal data beyond what is necessary to reproduce the issue. The security mailbox is monitored through the shared support operation.
Do not access another customer’s data, disrupt service, perform denial-of-service testing, or publish an unremediated issue. We will preserve a timestamped report and coordinate next steps after production support ownership is assigned.