NEWFSMA 204 & SQF Edition 9 Evidence Templates are now live.Run free spreadsheet audit →
Home/Legal/Security Policy
TECHNICAL CONTROLS & VULNERABILITY POLICY

Security & Vulnerability Policy

Effective Date: September 5, 2026 Entity: DragonVerse Media Inc. (Colorado, USA) Posture: Zero-Trust · Multi-Tenant Isolated
Security Sections

1. Security Architecture & Zero-Trust Principles

Evidlane is designed around defense-in-depth, strict organizational tenancy, private object storage, expiring single-use supplier upload links, and immutable audit event logging.

We safeguard confidential food manufacturing specifications, GFSI audit certificates, third-party laboratory results, and proprietary supplier networks with bank-grade controls.

2. Multi-Tenant Logical Separation

Evidlane enforces strict logical data partitioning. Every single database query for suppliers, evidence items, documents, and audit logs is constrained by foreign-key scoped organizationId validation.

  • Zero Vendor Cross-Contamination: External suppliers only have access to their specific requested evidence upload form. They can never view other suppliers, pricing, or internal review comments.
  • Role-Based Access Control (RBAC): Granular permissions separate Owner, Admin, and QA Reviewer permissions with server-side validation on every API route.
  • Stateless WebCrypto Session Tokens: Authenticated sessions use pure WebCrypto HMAC cryptographic signatures with session rotation.

3. Encryption Standards (Rest & Transit)

In Transit: All HTTP traffic to getevidlane.com is strictly forced over TLS 1.3 with HSTS enabled. Unencrypted HTTP traffic is rejected.

At Rest (Private Cloudflare R2 Vault): Supplier compliance documents are stored in private Cloudflare R2 buckets encrypted with AES-256. Files are never public. Downloads are brokered exclusively via short-lived (300-second TTL) presigned URLs generated on demand for authenticated QA users.

Database Storage: Neon PostgreSQL databases operate on encrypted volumes with automatic point-in-time recovery (PITR).

4. Antivirus Quarantine & Magic Byte Ingestion

To protect QA teams from malicious supply chain payloads, Evidlane implements automated file validation:

Magic-Byte Type Verification
Files are checked for actual binary signatures (PDF, PNG, JPG, CSV), blocking renamed executable payloads.
ClamAV Antivirus Pipeline
Automated asynchronous file scan runs immediately upon upload. Infected files are instantly quarantined before QA preview.

5. Immutable Audit Event Ledger

To satisfy GFSI (SQF Clause 2.3.4 / BRCGS Section 3.5) audit trail standards, Evidlane records all critical system activities in an append-only audit event table:

  • Creation, update, and revocation of single-use upload tokens.
  • Vendor upload timestamps, file checksums, and IP addresses.
  • Human QA approval and rejection decisions with recorded reasons.
  • One-click ZIP audit export events.

6. Vulnerability Disclosure & Bug Bounty Policy

Evidlane welcomes responsible security research. If you discover a vulnerability in our software or infrastructure, we ask that you disclose it responsibly:

Safe Harbor Commitment:Evidlane will not pursue legal action against security researchers who conduct good-faith research, do not access customer data without permission, avoid disruption of production services, and provide us reasonable time to remediate before public disclosure.
  • Report vulnerabilities directly to security@getevidlane.com or defhnhqf@gmail.com.
  • Our security engineering team acknowledges submissions within 24 hours.
  • We provide triage updates every 48 hours until remediation is deployed.

7. Incident Response & Disaster Recovery

Our operational response targets:

  • Recovery Point Objective (RPO): < 1 hour (continuous PostgreSQL streaming backups).
  • Recovery Time Objective (RTO): < 4 hours for complete system reconstitution.
  • Breach Notification: Affected enterprise customers will be notified within 72 hours of any verified breach impacting customer data.

8. Security Team & Questionnaire Inquiries

To request a vendor security questionnaire (SIG Lite, CAIQ) or review SOC 2 readiness documentation, contact:

Security & Trust Team

DragonVerse Media Inc. · Attn: Chief Information Security Officer
Email: security@getevidlane.com / defhnhqf@gmail.com
Live Status: https://getevidlane.com/status