Aller au contenu
shadgramers

Security

We sell hosted services: security is not an option billed on top, it is applied by default to every deployment. This page summarises what is actually in place and where to report a problem.

Systematic hardening

Unprivileged containers (capabilities dropped, read-only filesystem, non-root user), audited hosts (auditd, fail2ban, automatic security updates), key-only SSH.

Per-deployment isolation

One customer means one dedicated network. Traffic between two deployments is blocked at the firewall, never at application level only. Databases are never exposed to the internet.

Strong authentication

Self-hosted Keycloak identity provider, mandatory second factor on all administrative access, revocable sessions, passwords never stored in clear text.

Logging and traceability

Centralised structured logs, append-only audit trail for every administrative action, pseudonymised IP addresses, retention limited to what is necessary.

Report a vulnerability

Write to security@shadgramers.tech. Acknowledgement within 5 working days. This is a recognition programme: it is not funded, no bounty is paid — we would rather say so before you invest your time.

Transparency in operation