Security
Last reviewed 28 September 2026
Promtact Enterprise is self-hosted software. This page describes its operating boundary, the security properties worth reporting and the reporting route.
Enterprise access control, auditability, deployment boundaries and assessment status are summarized in the Enterprise security review.
Reporting a vulnerability
Send suspected vulnerabilities privately to contact@promtact.com. Do not publish exploit details before a fix and coordinated disclosure are available.
What is worth reporting
| Surface | Why it matters |
|---|---|
| Authentication and authorization | A path that bypasses role, tenant, project or execution-scope enforcement. |
| Execution isolation | A way for a job to escape its declared namespace, target or resource boundary. |
| Evidence integrity | A way to alter a signed result without detection or bind it to the wrong execution. |
| Secrets | Credentials exposed through logs, reports, generated manifests or retained resources. |
| Cleanup | Run-owned credentials or privileged resources that remain after documented cleanup. |
Bounded claims
Each verification result establishes only the properties, faults, versions and execution boundary recorded with it. A documented bound that does not match observed behavior is a valid security or correctness report when accompanied by a reproducible measurement.
This website
The site is static and served from Cloudflare Pages. It uses no analytics, cookies, third-party scripts or web fonts. Machine-readable contact details are available at /.well-known/security.txt.