Live security posture
Security status
Every security control we operate, scanned or probed continuously, with the latest result. No marketing claims — just data. A tile is green when the control is healthy, amber when it needs attention, red when action is required, and grey when we are awaiting the next run.
Code & supply chain
Source-code analysis, dependency vulnerabilities, secret detection.
Static code analysis
scan output missing
21 hours ago
Static code analysis (complementary)
2 error · 6 warning
21 hours ago
Static code analysis (project rules)
0 error · 0 warning
21 hours ago
Dependency vulnerabilities
0 critical · 0 high · 0 moderate · 0 low
21 hours ago
Known-vulnerable libraries
0 known-vulnerable libraries
21 hours ago
Dependency advisories
0 open advisories
5 hours ago
Supply-chain integrity
0 vulnerabilities
21 hours ago
Secret leak detection
0 leaked secrets in history
21 hours ago
Filesystem & misconfiguration scan
0 critical · 0 high
21 hours ago
Infrastructure-as-code scan
0 failed · 3400 passed
21 hours ago
GitHub Actions security audit
scan output missing
21 hours ago
Web application
Active scans against the running site for known classes of vulnerability.
API & authentication
Continuous tests of authentication, authorization, and webhook integrity.
Network & TLS
Transport security, certificate health, exposed surface area.
DNS & email integrity
Domain configuration, anti-spoofing, certificate transparency.
Browser security
Response headers + Content Security Policy as observed by an external probe.
Threat intelligence
Breach databases, attack-surface drift, suspicious traffic patterns.
Audits & exercises
Independent assessments and internal drill cadence.
How this page works
Tiles are powered by automated scanners (run on schedule), live external probes (run hourly), and manually-recorded artefacts (audits, drills, tabletops). A tile flips to grey if its expected cadence elapses without a fresh result — "we don't know" is more honest than a stale green dot.
Procurement teams: this page reflects current state. For the underlying policies, sub-processor list, and signed documentation, /security and our CAIQ-aligned questionnaire.