Trust & security
What we can show you today, and what is still being built.
This page describes Carbonex as it stands right now: what is built and operating, what is still being built, and what is only planned. It does not assert compliance with any external standard — a mapping or a control described here is not a certification.
Account security
Multi-factor authentication is available. A policy set per organisation can require it for every member or for administrators only, using a one-time code from an authenticator app together with printed recovery codes.
Single sign-on through Microsoft Entra ID is available, including automatic account creation the first time someone signs in through it.
Single sign-on through SAML is still in development. The sign-in screen for it exists, but it does not yet accept a real sign-in.
Access control and tenant separation
Every organisation using Carbonex sees only its own records. That separation is enforced today by rules checked on every request a page or a connected system makes.
A further, independent layer of separation enforced by the database itself, behind the one described above, is still being built.
Data protection
Every connection to Carbonex, from a browser or from a connected system, is encrypted in transit.
A small number of especially sensitive values — the credentials held for a connected system, and the codes behind two-factor authentication — are encrypted a second time, independently of the database itself. Encryption at rest for the database is set in the production hosting configuration and will apply once production hosting is live; most other data will rely on that setting rather than a further layer of its own.
Hosting and data residency
Keeping a particular organisation’s data within one region is a setting that can be applied; it is not yet something the platform enforces automatically on its own.
Backups and recovery
Daily backups with seven-day retention are part of the production hosting configuration and will run once production hosting is live.
Copying backups to a second region, and regularly rehearsing a full restore to prove it works, are both still planned.
Secure development
Part of the codebase is scanned automatically for common coding mistakes before a change is released; widening that scan to cover the rest of the codebase is still being built.
Scanning the open-source components Carbonex depends on for known vulnerabilities, and testing the running application from the outside the way an attacker would, are both planned and not yet in place.
Independent testing
An independent penetration test is planned. No date has been set.
Certifications
Carbonex holds no independent security certification today. If that changes, this page will name the certification, the certifying body and the date.
Status
There is no public status page yet.
Responsible disclosure
If you believe you have found a security issue, our disclosure policy is published at security.txt, or you can write to us directly at contact@yottanexa.com.