08Security
Security as a structural decision.
Identity, isolation and assurance are part of how the platform is built rather than a hardening pass added before a release.
This page describes an architecture. It does not claim a certification, an audit outcome or a compliance status that VEXO has not obtained.
Architecture
Three layers
Identity decides who acts, isolation decides what they can reach, assurance decides what can be proven afterwards.
Identity
- Multi-factor authentication
- Role-based access
- Secure sessions
Isolation
- Tenant isolation
- Encrypted management traffic
- Secrets protection
Assurance
- Audit logging
- Vulnerability management
- SBOM
- Signed updates
Claims
What this page does not say.
Security pages are where marketing language does the most damage. These are the claims VEXO will not make.
- VEXO is not described as “fully secure”, “unbreakable” or “military grade”. No platform is, and the phrase tells a reader nothing.
- VEXO does not list compliance certifications it has not been assessed against. If a certification is not named here, it has not been obtained.
- VEXO does not publish penetration-test outcomes as a marketing badge. A VAPT summary will be published as a document with a date and a scope.
- VEXO does not claim an availability or uptime figure. Availability is a property of a deployment, not of software.
Documents
Security documentation
Each document below will be published with a date and a scope. None of them is available yet.
Security Whitepaper
Architecture, threat model and management-plane boundaries.
Vulnerability Disclosure
How to report a suspected vulnerability in VEXO.
Security Advisories
Published advisories and affected version ranges.
SBOM Information
Component inventory for released platform builds.
VAPT Summary
Summary findings from independent security testing.
Security
Ask the awkward questions.
Threat model, management-plane boundaries, update signing. If the answer is “not yet”, you will get that answer.
