SecurePM
Security FAQ

Pre-answered questions for your review.

Derived from the design-partner security packet. Status: v0, design-partner stage — no SOC 2 yet; architecture is built for buyer-owned audit.

1. Where does our data reside?

Customer-owned. Content lives in your data plane (Cloudflare account or air-gapped VPC). The vendor stores only license keys, opaque instance ids, and content-free usage counts.

2. Who are subprocessors?

Shared. Data plane: Cloudflare (your account) or your VPC. Inference: Workers AI or the model endpoint you configure. Vendor billing: LemonSqueezy (license only, content-free). The exact configured content destinations are shown by GET /egress; the vendor domain is excluded.

3. Encryption in transit and at rest?

Shared. HTTPS on all planes. Content at rest in your Vectorize/D1 under Cloudflare platform encryption. No vendor copy to encrypt.

4. Is content used to train models?

No. RAG at request time only. Nothing sent to a training pipeline. Stated verbatim in GET /egress note.

5. What egress connections exist?

Verifiable. Complete allowlist at GET /egress. Default Workers AI: empty array. Custom provider: exactly your gateway/Bedrock host. securepm.dev provably absent.

6. Service-to-service auth?

Shared. Boundary A: Bearer shared secret, constant-time compare, fail-closed. /healthz reports honest auth state.

7. Who can access issue content?

Customer-owned. Only your Jira app + your Worker. Vendor never receives issue text, embeddings, or model output.

8. Audit trail?

Customer-owned D1. Nine v1 columns plus warnings_text and compliance_action. Queryable by your compliance team in your store.

9. Invalid custom-field values?

Dropped with reason in warnings; never written to Jira. Error vocab: rejected: not in allowed options.

10. Compliance rules (FR-9)?

Configurable rules can require approval or block drafts. compliance_action recorded in audit row; block returns HTTP 422.

11. Signed attestation?

Ed25519 statement of egress allowlist at GET /attestation. Verify offline with pinned public key.

12. Air-gap deployment?

Reference Python backend runs with zero network. Offline Ed25519 license gates /draft and /ingest.

13. Data retention?

Customer-owned. You control D1/Vectorize retention and export policy.

14. Incident response?

Design-partner contact agreed at pilot start. Vendor receives no content to breach.

15. SOC 2 / ISO 27001?

Not yet. Honest v0 posture. Controls are architectural (topology) plus buyer-runnable CI gates.

16. Penetration testing?

Buyer can run CI egress/auth gates against their deployment. Formal third-party pentest deferred.

17. SSO / RBAC?

Maps to existing Jira and identity controls. Enterprise rollout includes architecture workshop.

18. SIEM integration?

Optional webhook posts audit payloads to customer SIEM URL. URL validated; network errors soft-fail.

19. Marketplace data handling?

Forge/Connect are thin front-ends; content passes through Atlassian to your Worker only.

Full questionnaire

Need the design-partner security packet?

Architecture one-pager, 20 questionnaire answers, compliance pack mapping, and buyer-runnable CI gates from docs/design-partner-kit/.

Request full packet