Security overview
Security
Veracto is being built around explicit service approval, project-scoped context and visible work receipts. This page describes the current public-site controls and the product principles guiding early access.
Public-site controls
The production site runs in a restricted container with a read-only application filesystem, minimal Linux capabilities and loopback-only application exposure behind the web proxy. Waitlist and first-party event records are kept in a separate persistent data volume.
Product access principles
Early-access connections are designed to require explicit approval and to stay associated with a specific project topic. The interface will distinguish requests, the services used, completed steps and returned sources. These are design principles for a product still in development, not a certification claim.
Responsible disclosure
If you believe you found a security issue, email [email protected] with a concise description, affected URL and reproduction steps. Do not access data that is not yours, degrade availability or publish a vulnerability before we have had a reasonable opportunity to respond.
What to expect
We will acknowledge good-faith reports, investigate their impact and communicate material remediation progress when possible. Please do not include credentials, personal data or other secrets in an initial report.