Report a vulnerability
Email security@anterislab.com with a description, reproduction steps and any proof of concept. Encrypt sensitive material with our PGP key on request.
security.txt · /.well-known/security.txt
Scope
In scope: the AnterisLab web application, the decision API, the SDKs and the public documentation site. Out of scope: third-party sub-processors, social engineering, physical attacks, and volumetric denial of service.
Response targets
| Phase | Target |
|---|---|
| Initial acknowledgement | Within 24 hours |
| Triage and severity assignment | Within 72 hours |
| Critical remediation | 24 hours from triage |
| High remediation | 72 hours from triage |
| Medium remediation | 1 week from triage |
| Low remediation | Next sprint |
Controls in place
| Area | Control |
|---|---|
| Identity | Roles and permissions are sourced from the IdP on every login; local roles are a cache and never override the IdP. |
| Sessions | HttpOnly; Secure; SameSite=Lax cookies. No token is ever exposed to JavaScript or returned in a response body. |
| Tokens | Signed algorithms pinned at verification time; the token’s own alg claim is never trusted and none is rejected. |
| Secrets | Environment-injected, fail-fast at startup. No secret literal exists in source and no fallback default is permitted. |
| Data access | Parameterised queries only; every external input validated against a strict schema at the trust boundary. |
| Data residency | Application deployed on Vercel (United States); the database and its backups remain in the EU (Ireland). Operated by SAASDEVSOLUTIONS LTD, registered in the United Kingdom. |
| Logging | Tokens, passwords, keys and PII are masked or omitted from every log stream. |
| Transport | HSTS with preload, TLS 1.2+, restrictive CSP and a CORS allowlist — never a wildcard on authenticated endpoints. |
| Abuse | Rate limiting on login, registration, password reset, MFA and refresh, keyed by IP and by user. |
Please do not test against production data, run automated scanners at volume, or publicly disclose a finding before a fix is available. We will credit you in the acknowledgements unless you prefer to stay anonymous.
Who to contact
Security reports and questions about our controls should be sent to security@anterislab.com. The service is operated by SAASDEVSOLUTIONS LTD, registered in England and Wales, Company Number 17362476, with its registered office at 167-169 Great Portland Street, 5th Floor, London, United Kingdom.
Acknowledgements
No public acknowledgements yet. Responsible reports are credited here after remediation.