Security, without badge theatre.

The repository supports specific engineering claims. This page does not imply certification, a completed external penetration test, an uptime promise or a data-residency guarantee.

Server-side access checks

Client identifiers are not treated as proof of access. Requests are authenticated and scoped on the server.

Built and verified

Database-level tenant isolation

Tenant records are protected with row-level security rather than application filtering alone.

Built and verified

Verified provider events

Payment, communications and AI-provider events include signature verification and safe retry handling.

Built and verified

Separate administrative access

Administrative privileges are modelled separately, authorised individually and designed for auditable actions.

Built and verified

Not claimed

These omissions are intentional until direct evidence and approval exist.

No SOC 2 claimNo ISO 27001 claimNo Cyber Essentials claimNo completed external penetration-test claimNo region or residency guaranteeNo uptime SLA

Report a security issue.

This form routes to trust@chatursystems.com. Provide only the detail needed to understand the issue; do not include credentials or customer data.

Read the legal security draft
Secure formSent to the appropriate Chatur Systems mailbox. Nothing is added to a mailing list.

Please don't include credentials, customer data, or more personal information than we need to understand and act on your report. If it involves a proof-of-concept file, describe it here — we'll follow up about sharing it securely.