Security
Private evidence deserves explicit boundaries.
Ombudex separates public projections from private source data and treats every external fetch, upload, integration, and tenant boundary as a security decision.
Last updated: 30 August 2026
Application controls
Authentication, verified email requirements, server-side validation, authorization policies, rate limits, signed links, encrypted credentials, and append-only audit events protect sensitive workflows.
Private resources are authorized by organization ownership rather than by identifier obscurity.
Evidence files
Evidence is stored outside the public filesystem, renamed, hashed, MIME-checked, size-limited, and scanned asynchronously. A missing scanner never produces a false clean status.
Outbound requests
Domain verification and monitoring reject loopback, private, link-local, multicast, reserved, and cloud-metadata destinations. DNS is revalidated across redirects and response size and duration are bounded.
Responsible disclosure
Report a suspected vulnerability through the verified contact address published in the legal notice, with steps to reproduce and limited proof. Do not access other users’ data, disrupt service, or include unnecessary personal data.