Security

Security at Sectie.

Security is treated as an engineering constraint across Sectie's systems, software and product development. This page describes how we approach it and how to reach us about a security issue.

Principles

How we approach security.

01

Security by design

Data boundaries, access control and failure modes are decided before features are built.

02

Least necessary access

People, services and integrations receive the access they need for a task, and no more.

03

Clear data boundaries

Customer data stays within defined boundaries, under the customer's control.

04

Evidence over unsupported claims

We do not publish metrics, certifications or guarantees we cannot show.

05

Human oversight for AI-assisted workflows

AI assistance remains subject to explicit human and policy boundaries.

06

Observable system behavior

Systems are built so that what they did, and why, can be inspected afterwards.

Vulnerability disclosure

Reporting a security issue.

If you believe you have identified a security issue affecting sectie.net or Sectie software, contact contact@sectie.net.

Please include "Security" in the subject line, provide enough technical detail to reproduce the issue, avoid accessing or modifying data that is not yours, and allow reasonable time for investigation and remediation before public disclosure.

Machine-readable contact: https://sectie.net/.well-known/security.txt