Skip to main content

Security

Private evidence deserves explicit boundaries.

Ombudex separates public projections from private source data and treats every external fetch, upload, integration, and tenant boundary as a security decision.

Last updated: 30 August 2026

Application controls

Authentication, verified email requirements, server-side validation, authorization policies, rate limits, signed links, encrypted credentials, and append-only audit events protect sensitive workflows.

Private resources are authorized by organization ownership rather than by identifier obscurity.

Evidence files

Evidence is stored outside the public filesystem, renamed, hashed, MIME-checked, size-limited, and scanned asynchronously. A missing scanner never produces a false clean status.

Outbound requests

Domain verification and monitoring reject loopback, private, link-local, multicast, reserved, and cloud-metadata destinations. DNS is revalidated across redirects and response size and duration are bounded.

Responsible disclosure

Report a suspected vulnerability through the verified contact address published in the legal notice, with steps to reproduce and limited proof. Do not access other users’ data, disrupt service, or include unnecessary personal data.