Security & Vulnerability Policy
1. Security Architecture & Zero-Trust Principles
Evidlane is designed around defense-in-depth, strict organizational tenancy, private object storage, expiring single-use supplier upload links, and immutable audit event logging.
We safeguard confidential food manufacturing specifications, GFSI audit certificates, third-party laboratory results, and proprietary supplier networks with bank-grade controls.
2. Multi-Tenant Logical Separation
Evidlane enforces strict logical data partitioning. Every single database query for suppliers, evidence items, documents, and audit logs is constrained by foreign-key scoped organizationId validation.
- Zero Vendor Cross-Contamination: External suppliers only have access to their specific requested evidence upload form. They can never view other suppliers, pricing, or internal review comments.
- Role-Based Access Control (RBAC): Granular permissions separate Owner, Admin, and QA Reviewer permissions with server-side validation on every API route.
- Stateless WebCrypto Session Tokens: Authenticated sessions use pure WebCrypto HMAC cryptographic signatures with session rotation.
3. Encryption Standards (Rest & Transit)
In Transit: All HTTP traffic to getevidlane.com is strictly forced over TLS 1.3 with HSTS enabled. Unencrypted HTTP traffic is rejected.
At Rest (Private Cloudflare R2 Vault): Supplier compliance documents are stored in private Cloudflare R2 buckets encrypted with AES-256. Files are never public. Downloads are brokered exclusively via short-lived (300-second TTL) presigned URLs generated on demand for authenticated QA users.
Database Storage: Neon PostgreSQL databases operate on encrypted volumes with automatic point-in-time recovery (PITR).
4. Antivirus Quarantine & Magic Byte Ingestion
To protect QA teams from malicious supply chain payloads, Evidlane implements automated file validation:
5. Immutable Audit Event Ledger
To satisfy GFSI (SQF Clause 2.3.4 / BRCGS Section 3.5) audit trail standards, Evidlane records all critical system activities in an append-only audit event table:
- Creation, update, and revocation of single-use upload tokens.
- Vendor upload timestamps, file checksums, and IP addresses.
- Human QA approval and rejection decisions with recorded reasons.
- One-click ZIP audit export events.
6. Vulnerability Disclosure & Bug Bounty Policy
Evidlane welcomes responsible security research. If you discover a vulnerability in our software or infrastructure, we ask that you disclose it responsibly:
- Report vulnerabilities directly to security@getevidlane.com or defhnhqf@gmail.com.
- Our security engineering team acknowledges submissions within 24 hours.
- We provide triage updates every 48 hours until remediation is deployed.
7. Incident Response & Disaster Recovery
Our operational response targets:
- Recovery Point Objective (RPO): < 1 hour (continuous PostgreSQL streaming backups).
- Recovery Time Objective (RTO): < 4 hours for complete system reconstitution.
- Breach Notification: Affected enterprise customers will be notified within 72 hours of any verified breach impacting customer data.
8. Security Team & Questionnaire Inquiries
To request a vendor security questionnaire (SIG Lite, CAIQ) or review SOC 2 readiness documentation, contact:
Security & Trust Team
DragonVerse Media Inc. · Attn: Chief Information Security Officer
Email: security@getevidlane.com / defhnhqf@gmail.com
Live Status: https://getevidlane.com/status