Three-plane architecture, threat model, data inventory, and live egress proof.
Open security review →Evidence your security team can verify before purchase.
SecurePM is v0 and design-partner stage. We publish reproducible proofs — not customer logos — so reviewers can inspect boundaries, egress, and audit traceability themselves.
Start here for procurement and security review.
Twenty pre-answered questionnaire items: residency, subprocessors, training, auth, audit.
Read security FAQ →Week-by-week rollout steps for Cloud, Data Center, and air-gapped paths.
Open checklist →Turn a rough product note into a Jira-ready issue, then review project fields, sources, and the content boundary.
Run test drive →Run these commands during review.
curl -sS https://api.securepm.dev/egress | jq # Expect: only your model endpoint — never securepm.dev curl -sS https://api.securepm.dev/attestation | jq # Signed Ed25519 statement of the egress allowlist curl -sS https://securepm.dev/api/privacy | jq # Content-free licensing boundary (control plane)
Pin the public key from /attestation and verify offline with the MIT @opensyber/spm-attest CLI shipped in this repo.
What gets logged in your tenant.
| Record | Where | Fields |
|---|---|---|
| Draft audit row | Customer D1 | actor, project, intent, model, citations, fields_set, warnings, compliance_action |
| Validator rejections | Same audit row | warnings_text with per-field reasons |
| Compliance blocks | 422 response + audit | compliance_action = block_draft | require_approval |
| License check | Vendor control plane | key, opaque instance id, content-free draft count only |
What we do not claim yet.
v0 design-partner stage. Architecture is built for buyer-owned audit; formal certification is deferred.
Evidence is reproducible tests and live endpoints, not reference customers.
SecurePM is a working codename. Marketplace listing waits on validation GO.
Need the complete security packet?
Architecture one-pager, CI gate suite, compliance pack mapping, and questionnaire answers for your review email.