promtact

Security

Last reviewed 28 September 2026

Promtact Enterprise is self-hosted software. This page describes its operating boundary, the security properties worth reporting and the reporting route.

Scope of this page

Enterprise access control, auditability, deployment boundaries and assessment status are summarized in the Enterprise security review.

Reporting a vulnerability

Send suspected vulnerabilities privately to contact@promtact.com. Do not publish exploit details before a fix and coordinated disclosure are available.

What is worth reporting

SurfaceWhy it matters
Authentication and authorizationA path that bypasses role, tenant, project or execution-scope enforcement.
Execution isolationA way for a job to escape its declared namespace, target or resource boundary.
Evidence integrityA way to alter a signed result without detection or bind it to the wrong execution.
SecretsCredentials exposed through logs, reports, generated manifests or retained resources.
CleanupRun-owned credentials or privileged resources that remain after documented cleanup.

Bounded claims

Each verification result establishes only the properties, faults, versions and execution boundary recorded with it. A documented bound that does not match observed behavior is a valid security or correctness report when accompanied by a reproducible measurement.

This website

The site is static and served from Cloudflare Pages. It uses no analytics, cookies, third-party scripts or web fonts. Machine-readable contact details are available at /.well-known/security.txt.