الأمان والإفصاح عن الثغرات
آخر تحديث: 2026-08-15
Security is the product's premise, not an add-on: Almanexa exists so organizations can trust a record. This page describes how we protect the Service and how to report a vulnerability responsibly.
How Almanexa protects customer data
- Dedicated instances: each Almanexa Cloud customer runs in its own instance with its own database. There is no shared application container between customers.
- Encryption at rest: sensitive content is encrypted at rest inside the product itself, not only at the disk layer.
- Tamper-evident history: governance actions are written to an append-only, hash-chained, signed record, so any alteration would show.
- Least-privilege access: machine access uses scoped, revocable keys; approvals enforce separation of duties, so no one approves their own work.
- Source-available core: the core is published under BSL 1.1, so how approvals are enforced and how the record is sealed can be read and verified rather than taken on trust.
We do not currently claim third-party certifications. Where a certification is achieved, we will name it here rather than implying it beforehand.
Reporting a vulnerability
If you believe you have found a security vulnerability in Almanexa, the website or the Cloud service, we want to hear from you.
- Email [email protected] with "Security" in the subject line. Include what you found, where, and steps to reproduce it.
- We will acknowledge your report promptly, keep you informed while we investigate, and tell you when the issue is resolved.
- Please give us a reasonable opportunity to fix the issue before public disclosure, and do not access, modify or exfiltrate data that is not yours in the course of research.
Safe harbour for good-faith research
We will not pursue legal action for good-faith security research that respects the rules above, stays within your own accounts and test data, and avoids harming the Service or other customers. Testing against another customer's instance is never authorised.
Contact
Security questions and reports: [email protected].