AnterisLab
Resources · Security

Security at AnterisLab

How we protect the decision path, how to report a vulnerability, and the controls that stand between an autonomous agent and an irreversible mistake.

Report a vulnerability

Email security@anterislab.com with a description, reproduction steps and any proof of concept. Encrypt sensitive material with our PGP key on request.

security.txt · /.well-known/security.txt

Scope

In scope: the AnterisLab web application, the decision API, the SDKs and the public documentation site. Out of scope: third-party sub-processors, social engineering, physical attacks, and volumetric denial of service.

Response targets

PhaseTarget
Initial acknowledgementWithin 24 hours
Triage and severity assignmentWithin 72 hours
Critical remediation24 hours from triage
High remediation72 hours from triage
Medium remediation1 week from triage
Low remediationNext sprint

Controls in place

AreaControl
IdentityRoles and permissions are sourced from the IdP on every login; local roles are a cache and never override the IdP.
SessionsHttpOnly; Secure; SameSite=Lax cookies. No token is ever exposed to JavaScript or returned in a response body.
TokensSigned algorithms pinned at verification time; the token’s own alg claim is never trusted and none is rejected.
SecretsEnvironment-injected, fail-fast at startup. No secret literal exists in source and no fallback default is permitted.
Data accessParameterised queries only; every external input validated against a strict schema at the trust boundary.
Data residencyApplication deployed on Vercel (United States); the database and its backups remain in the EU (Ireland). Operated by SAASDEVSOLUTIONS LTD, registered in the United Kingdom.
LoggingTokens, passwords, keys and PII are masked or omitted from every log stream.
TransportHSTS with preload, TLS 1.2+, restrictive CSP and a CORS allowlist — never a wildcard on authenticated endpoints.
AbuseRate limiting on login, registration, password reset, MFA and refresh, keyed by IP and by user.

Please do not test against production data, run automated scanners at volume, or publicly disclose a finding before a fix is available. We will credit you in the acknowledgements unless you prefer to stay anonymous.

Who to contact

Security reports and questions about our controls should be sent to security@anterislab.com. The service is operated by SAASDEVSOLUTIONS LTD, registered in England and Wales, Company Number 17362476, with its registered office at 167-169 Great Portland Street, 5th Floor, London, United Kingdom.

Acknowledgements

No public acknowledgements yet. Responsible reports are credited here after remediation.