AssuranceNo third-party penetration test
Nobody outside this project has attacked it. The security work described above is our own, checked by our own tests. An external test has not been commissioned, and until it has, treat this page as a description of intent backed by code rather than as an independent finding.
AssuranceNo SOC 2, no ISO 27001, no formal certification
There is no audit report to send your procurement team. If a certificate is a hard requirement for you, this is not yet the product for you, and we would rather you learned that here than in week six.
ResilienceOne region, and no point-in-time recovery
The restore rehearsal proves the dump-and-restore pair. It does not prove write-ahead-log archiving, point-in-time recovery, or that the store holding the dumps is durable. There is no second region and no documented failover time.
AccessNo single sign-on
There is no SAML or OpenID Connect. Nobody signs in with your company identity provider, there is no domain-based auto-provisioning and no group-to-role mapping. Accounts are created in the product and carry their own password and second factor.
AccessYou cannot build a custom role
Sixteen roles ship configured and you assign and revoke those. The permissions to create a role are in the catalogue with no screen behind them, so a bundle that is nearly right cannot yet be edited into one that is exactly right.
AccessNo organisation-wide "everyone must use a second factor"
A second factor is mandatory for accounts holding one of the thirteen dangerous permissions, and optional for everybody else. You cannot yet require it of the whole company.
AccessNo rate limiting on sign-in
The per-account lockout ladder above is real and works. There is no throttle in front of it, on the sign-in endpoint or on export and notification endpoints, so an attacker spreading guesses across many addresses meets the ladder but not a rate limit.
AccessThe compromised-password check is a short deny-list
Fifteen obvious long passwords, bundled. Not the top hundred thousand, and not a range query against a breach corpus, both of which the specification asks for.
The recordThere is no audit-trail screen for operators
Every change is written, masked, and cannot be edited or deleted — that part is real. But there is no per-record Activity tab in the operator app and no export of the trail. Audit rows are readable through the platform console only, which means today you would ask us for them.
The recordThe audit table is not partitioned, and nothing prunes it
It grows for ever. There is no monthly partition, no retention job and no archive-and-drop.
ApprovalsNothing escalates an approval that is ignored
You can set "escalate after 48 hours" and it is stored and displayed. No job acts on it, so an unapproved request waits until somebody looks at the queue.
ApprovalsOne rule decides, and there is no chain
The first rule that catches a request wins. There is no two-step ladder, no "manager then director", and no parallel approvers.
ApprovalsFour of the eight approval kinds have nothing raising them yet
Discounts, write-offs, contract variations and cheque postponements do raise approvals. Contracts, refunds and expenses are modelled but nothing calls them, and the disciplinary approval is raised only by an eviction notice.
Data rightsNo per-person export, no erasure, no organisation export
You cannot yet produce everything held about one occupant, erase or anonymise them, or take a full copy of your organisation out on your own. Ask us and it is a manual job.
DeliveryNothing sends until you configure your own mail relay
Notifications and alerts are composed, suppressed, de-duplicated, digested and logged. With no relay configured, the log records the attempt and the reason rather than a failure that looks like a success. The delivery guarantees are your provider’s, not ours.
Coverage53 of the 254 permissions are declared and demanded by nothing
Among them the role-editing keys, API keys, the audit export, most block, floor and unit verbs, and a handful of billing verbs. A test in the build records that number and fails if it rises, so the gap can shrink and cannot quietly grow — but today those keys govern nothing.
CoverageNo API keys, no webhooks carrying real events
A dangerous permission exists for API keys with no endpoint behind it. Webhook endpoints can be registered and a signed test delivery sent, but no business event is ever published to one.
CoverageA permission change does not reach an open browser instantly
The server is stricter than the specification asks — permissions are re-derived from the database on every single request, so a revoked grant stops working immediately. But there are no realtime events anywhere in the product, so the screen in front of the person learns about the change from a response header rather than being pushed.
One thing on this list is a deliberate difference from the specification rather than a gap: permission changes are not pushed to open browsers. The server is stricter than asked — permissions are re-derived from the database on every single request, so a revoked grant stops working immediately rather than at the next refresh. What is missing is only the nudge that tells the screen to redraw.