Security
Security claims should be as inspectable as product claims.
One Lab publishes implemented controls and their limits. It does not present certification-readiness as certification or turn an architecture intention into a live control.
01 / Security
Follow the data flow.
A scoped source produces typed event evidence. Assure keeps that recorded evidence separate from derived inventory, process maps, controls and workpapers. A correction versions the interpretation; it does not silently rewrite the event.
02 / Security
Minimize what crosses the boundary.
Assure supports hash-only sources that cannot upload artifact bytes. Payload-enabled sources require an explicit policy change. Metadata and hashes can still be sensitive and remain subject to access, retention and privacy controls.
03 / Security
Separate organizations and roles.
Assure uses tenant-scoped database policies and server-side authorization. Cross-tenant requests are tested to avoid confirming that another organization's resource exists.
- Tenant-scoped row-level security
- Role-based API capabilities
- Scoped source credentials
- Exact-origin browser access controls
04 / Security
State the encryption and key boundary.
Current public services are delivered over HTTPS. This site does not yet publish a verified at-rest encryption and key-custody inventory, and it does not claim customer-managed keys, confidential computing or cryptographic shredding as generally available controls.
05 / Security
Preserve and check evidence history.
Event chains, signed checkpoints, external anchoring and offline verification are implemented. A current independent-human reconstruction acceptance remains outstanding; cryptographic integrity does not prove that an event's content was true.
06 / Security
Incident and availability commitments remain bounded.
A public security contact, response-time commitment, incident-notification schedule, availability status page and service-level promise are not configured in the website record. The production Observatory is protected by Cloudflare Access; that access check is read back after deployment.
07 / Security
Hosted is current; private modes are not claimed.
The public evidence supports the current hosted Cloudflare and Supabase deployment path. Private cloud, customer-managed keys, regional residency and confidential-compute options remain architecture targets unless a reviewed product record says otherwise.
08 / Security
No certification claim.
One Lab does not currently claim SOC 2, ISO 27001, ISO 42001 or another independent certification on this site. A readiness mapping or OSCAL-oriented export is not a certification.