Trust center · Security
Security is a delivery property, not a final checklist.
How WythinForge protects tenant boundaries, delivery context, software delivery integrity and customer-controlled releases.
Current Workspace controls
The Workspace is a tenant-isolated control plane. It does not ingest or execute customer production, HR, inventory, SAP or WMS transactions.
- Identity and membership are resolved on the server for protected operations; client-provided roles, owners and organization identifiers are not trusted.
- Row-level security is enabled on tenant-owned data and internal records are excluded from client-readable projections.
- MFA, private attachment storage, signed expiring download URLs, upload validation and append-only activity events protect high-impact workflows.
- Security headers, strict input validation and redaction rules reduce browser, integration and logging exposure.
Secure delivery baseline
Production delivery generates a retained CycloneDX SBOM, blocks HIGH and CRITICAL known vulnerabilities, scans for secrets and security misconfiguration, and signs the exact deployable artifact through the workflow identity.
- A Trust Receipt is generated and signed only after production promotion and health verification.
- The default lifecycle supports the current minor line and keeps the previous line on security-fix maintenance for 90 days.
- Rollback uses a protected workflow that verifies the selected deployment before and after promotion.
- A strict installation-record contract tracks version, deployment model, last contact, vulnerability posture and rollback target without client transaction data.
Report a vulnerability
Send a concise report to hello@wythinforge.com with the subject “Security”. Include the affected product and version, reproduction steps and impact. Do not include live customer data, credentials or destructive proof. Wythin will coordinate validation, remediation and disclosure with the reporter.
