Security

Security claims should be as inspectable as product claims.

One Lab publishes implemented controls and their limits. It does not present certification-readiness as certification or turn an architecture intention into a live control.

01 / Security

Follow the data flow.

A scoped source produces typed event evidence. Assure keeps that recorded evidence separate from derived inventory, process maps, controls and workpapers. A correction versions the interpretation; it does not silently rewrite the event.

02 / Security

Minimize what crosses the boundary.

Assure supports hash-only sources that cannot upload artifact bytes. Payload-enabled sources require an explicit policy change. Metadata and hashes can still be sensitive and remain subject to access, retention and privacy controls.

03 / Security

Separate organizations and roles.

Assure uses tenant-scoped database policies and server-side authorization. Cross-tenant requests are tested to avoid confirming that another organization's resource exists.

  • Tenant-scoped row-level security
  • Role-based API capabilities
  • Scoped source credentials
  • Exact-origin browser access controls

04 / Security

State the encryption and key boundary.

Current public services are delivered over HTTPS. This site does not yet publish a verified at-rest encryption and key-custody inventory, and it does not claim customer-managed keys, confidential computing or cryptographic shredding as generally available controls.

05 / Security

Preserve and check evidence history.

Event chains, signed checkpoints, external anchoring and offline verification are implemented. A current independent-human reconstruction acceptance remains outstanding; cryptographic integrity does not prove that an event's content was true.

06 / Security

Incident and availability commitments remain bounded.

A public security contact, response-time commitment, incident-notification schedule, availability status page and service-level promise are not configured in the website record. The production Observatory is protected by Cloudflare Access; that access check is read back after deployment.

07 / Security

Hosted is current; private modes are not claimed.

The public evidence supports the current hosted Cloudflare and Supabase deployment path. Private cloud, customer-managed keys, regional residency and confidential-compute options remain architecture targets unless a reviewed product record says otherwise.

08 / Security

No certification claim.

One Lab does not currently claim SOC 2, ISO 27001, ISO 42001 or another independent certification on this site. A readiness mapping or OSCAL-oriented export is not a certification.