VENTEX / Trust Center

Security that discloses its status.

This Trust Center separates active controls, internally verified states and planned capabilities. It does not replace an independent audit—it makes the current state easier to review.

VENTEXCONTROLLED
EVIDENCE
ActiveInternally verifiedPlannedSTATUS / 2026-08
Control catalogue

What protects today—and what is still missing.

ID-01Active

Device-bound sessions

Devices and refresh sessions are individually visible and revocable.

CT-02Active

Client-side content protection

Message and file content crosses the service boundary in protected form.

OP-03Internally verified

Reproducible release gate

Type checks, automated tests and production builds form the internal release evidence.

ST-04Active

Private object storage

Attachments use private storage and short-lived access paths instead of public buckets.

PR-05Internally verified

No advertising trackers

The product site and Connect pilot do not depend on advertising or profile analytics.

RC-06Active

Session and device revoke

Administrators and users can remove access without waiting for credentials to expire.

AU-07Planned

External cryptographic audit

Independent protocol and implementation review is required before broad security equivalence claims.

EN-08Planned

Enterprise identity

Organisation tenancy, SSO, SCIM and policy controls require dedicated models and acceptance.

Release evidence

Every release needs a chain of evidence.

  1. 01Source & dependency reviewPASS REQUIRED
  2. 02Type, lint and negative testsPASS REQUIRED
  3. 03Production build & migration checkPASS REQUIRED
  4. 04Runtime smoke testPASS REQUIRED
  5. 05Documented release decisionSIGNED DECISION
Security contact

Report a vulnerability responsibly.

Do not send secret keys, production credentials or personal content. Describe impact, reproduction steps and the affected version.

Contact security team