Skip to content

Security: softadastra/converdict

Security

SECURITY.md

SECURITY.md

Softadastra Converdict Security Policy

Version 1.0

1. Security Philosophy

Softadastra Converdict is a deterministic reliability validation engine designed for enterprise environments.

Security principles:

  • Explicit behavior over implicit assumptions
  • Deterministic execution paths
  • Minimal external dependencies
  • No hidden background services
  • Clear separation between validation engine and licensing systems

Security is treated as a core architectural requirement, not an afterthought.

2. Supported Versions

Security updates are provided for:

  • The latest stable release
  • The previous minor release, when applicable
  • Enterprise LTS versions under active contract

Unsupported versions may not receive patches.

3. Reporting a Vulnerability

If you discover a security vulnerability, do not open a public issue.

Report privately via:

security@softadastra.com

Please include:

  • A clear description of the vulnerability
  • Steps to reproduce
  • Affected version
  • Impact assessment if known
  • Any proof-of-concept material

We aim to acknowledge reports within 72 hours.

4. Vulnerability Handling Process

Upon receiving a report:

  1. Acknowledge receipt
  2. Assess severity
  3. Reproduce internally
  4. Develop mitigation or patch
  5. Coordinate responsible disclosure
  6. Publish advisory if required

Enterprise customers may receive early notification under contractual terms.

5. Threat Model Overview

Softadastra Converdict operates in controlled environments and is not designed as a public-facing web service.

Primary threat considerations:

  • Tampering with licensing mechanisms
  • Unauthorized access to validation reports
  • Injection of malicious scenarios
  • Abuse of chaos proxy capabilities
  • Supply chain compromise

Security design mitigations include:

  • Machine-bound license validation
  • Controlled failure injection boundaries
  • Strict CLI argument validation
  • Optional encrypted SaaS communication
  • Deterministic scenario isolation

6. Secure Deployment Guidelines

Recommended practices:

  • Run Converdict in isolated environments
  • Restrict network access to required targets only
  • Store reports in secured directories
  • Limit access to licensing credentials
  • Apply least-privilege principles
  • Enable operating system level sandboxing where possible

7. Cryptography

When encryption is used:

  • Industry-standard algorithms are selected
  • No proprietary cryptographic primitives are implemented
  • Secure random sources are required
  • Keys must be managed by the Licensee

Softadastra Converdict does not manage customer production secrets.

8. Licensing System Protection

The licensing subsystem may include:

  • Machine fingerprinting
  • Time-based lease validation
  • Integrity verification

Tampering, bypass attempts, or binary modification constitute license violation and may trigger enforcement measures.

9. Data Handling

Softadastra Converdict does not collect production data unless explicitly configured.

Optional telemetry for license validation may include:

  • Version information
  • License identifier
  • Activation status

No application payload inspection occurs unless part of an explicitly configured validation scenario.

10. Secure Build and Release Discipline

Each release must:

  • Be reproducible
  • Be tagged in source control
  • Pass internal test validation
  • Undergo security review for major changes

Enterprise builds may include integrity verification mechanisms.

11. Compliance and Audit

Enterprise customers may request:

  • Security architecture overview
  • High-level threat model documentation
  • Release validation confirmation

Softadastra Converdict is designed for environments requiring audit-ready validation artifacts.

12. Disclaimer

Softadastra Converdict is a validation engine. It does not replace secure coding practices, production monitoring, or formal security audits.

Licensee remains responsible for production security posture.

Softadastra Converdict

Prove convergence securely.

There aren't any published security advisories