Authenticated and allowlisted
The publishing interface requires signed-in identity and an authorized administrator email before content or files can be managed.
SECURITY · DATA HANDLING · RESPONSIBLE DISCLOSURE
This page distinguishes controls implemented on the current website from safeguards that must be defined for a specific AI vision, edge-compute or autonomous-machine deployment.
CURRENT WEBSITE CONTROLS
These controls protect the website and its evidence-publishing workflow. They do not constitute an external audit or a certification.
The publishing interface requires signed-in identity and an authorized administrator email before content or files can be managed.
Draft media is not exposed by the public asset route. An asset becomes public only when its parent evidence record is approved and published.
The CMS accepts a defined image, video and PDF MIME allowlist and enforces upload-size limits before storage.
Responses apply anti-sniffing, framing, referrer and browser-permission policies; administrative routes also receive no-index and no-store directives.
CMS metadata and uploaded files use separate managed data services. Access is mediated by application authorization and publication state.
A security.txt record gives researchers and customers a direct reporting path and links back to this policy.
No ISO 27001, SOC 2, penetration-test result or equivalent security certification is claimed on this website unless its verified scope and document are published in the Evidence Library.
PROJECT SECURITY FRAMEWORK
Edge-local, customer-controlled and connected architectures create different responsibilities. The signed project record should define the applicable controls.
Map sensors, networks, processing locations, stored artifacts, transfers and administrators.
Define roles, least-privilege access, approval points, credentials and offboarding.
Track source rights, dataset versions, model artifacts, configuration and acceptance evidence.
Inventory ports, protocols, dependencies, update authority, rollback and recovery paths.
Specify degraded modes, logging, fault handling, monitoring and safe machine behavior.
Agree detection, escalation, customer notification, evidence preservation and remediation ownership.
Define retention, return, deletion, credential revocation and decommissioning.
RESPONSIBLE DISCLOSURE
Include the affected URL or component, reproduction steps, potential impact and a safe way to contact you. Do not access, modify or retain data beyond what is necessary to demonstrate the issue.
PROJECT SECURITY REVIEW