1. Architecture summary
- License JWTs are signed with Ed25519. The private key is held offline. The public key is embedded in the customer binary at build time.
- A CycloneDX software bill of materials is generated for every release image. Ask us for the SBOM of a release you run.
- Customer portal passwords are hashed with argon2id. The engine hashes admin passwords with bcrypt by default, or argon2id when PASSWORD_HASH_ALGO is set to it.
- Every query on tenant data carries the tenant id, checked in the store, on PostgreSQL, MySQL and SQL Server.
- All HTTP endpoints emit hardened security headers (HSTS, CSP, X-Content-Type-Options, X-Frame-Options, Referrer-Policy).
- Rate limits, IP allowlists, and request-body caps are configurable per deployment.
2. Responsible disclosure
We welcome security reports. Email security@lyeve.com with reproduction steps and a clear impact statement. We acknowledge reports within 72 hours and aim to ship a fix or mitigation within 30 days for high and critical issues.
- Test only against accounts and infrastructure you own or have explicit permission to test.
- Do not perform denial-of-service tests, social engineering, or physical attacks.
- Give us a reasonable opportunity to remediate before public disclosure.
We credit reporters by name in the release notes unless you prefer to remain anonymous.
3. Out of scope
- Self-hosted deployments operated by customers. Those are your environment to secure.
- Reports of best-practice deviations without a concrete vulnerability (e.g. "no SPF record on a parked subdomain").
- Reports requiring physical access, social engineering of staff, or supply-chain compromise of upstream open-source projects.
4. Compliance posture
We do not hold a SOC 2 attestation. Two of our providers publish one: Amazon Web Services makes a SOC 2 report available to its customers, and Cloudflare states a SOC 2 Type II. We make no compliance claim on behalf of the others. Read each provider's own trust page, and see the subprocessors list for who processes what. We are happy to share architecture diagrams and policy documents under NDA on request.
5. Encrypted reports
We publish no PGP key today. If you need to send a report encrypted, write to security@lyeve.com and we will agree a channel with you first.