Security evidence map

Controls, boundaries, and evidence without inflated claims.

This public map distinguishes implemented product foundations, architectural controls, launch hardening, and deployment-specific evidence. It is an evaluation aid—not a certification statement.

Authentication & sessions
Implemented foundation

DB-backed users, server-side sessions, password controls, revocation, and privileged authorization are part of IDSENTRA-CORE.

Role-based access
Implemented foundation

Operational permissions and privileged actions are designed to be enforced server-side within the protected application boundary.

Operational/commercial separation
Architectural control

Patron identity, case, evidence, regulated-source credentials, and operational audit data remain outside IDSENTRA-DISTRO.

Signed licensing
Implemented foundation

Distribution state is issued as signed license material and verified locally by CORE; bounded cached lease behavior supports continuity.

Credential handling
Architectural control

Secrets, API keys, sessions, signing private keys, database credentials, and protected provider payloads are excluded from public surfaces and fleet telemetry.

Audit & retention
Operational control

Local audit/security records and retention controls are owned by CORE and configured according to deployment requirements.

Public lead intake
Launch hardening

The website accepts only business evaluation data, validates input server-side, supports provider-neutral rate controls, and fails closed when delivery is unavailable.

Privacy-minimized telemetry
Architectural control

DISTRO deployment health excludes patron searches, self-exclusion records, SSNs, DOBs, contact data, images, PDFs, credentials, tokens, and provider payloads.

Legal / certification evidence
Deployment-specific

Certifications, legal positions, processor disclosures, regulatory mappings, and customer-specific evidence are not claimed until verified for the actual deployment.