Access
Authenticated sessions, organization-scoped records, role checks for privileged actions, revocable credentials, and least-privilege operational access.
Trust center
Skrado is being hardened as a small, tenant-separated operations service. This page states the intended production baseline, current limitations, customer responsibilities, and how to report a concern.
Authenticated sessions, organization-scoped records, role checks for privileged actions, revocable credentials, and least-privilege operational access.
HTTPS for the hosted service, secure browser-session settings, security headers, request-size controls, and rate limiting at the application or reverse proxy.
Modern one-way password hashing, secrets supplied outside source control, protected API keys, and production startup that fails closed when required secrets are missing.
Validated inputs, explicit workflow transitions, tenant-aware object authorization, constrained file/static paths, dependency review, and automated tests for critical boundaries.
Restricted service accounts, database and backup permissions, health checks, patching, deployment review, incident runbooks, and restore testing.
Collection limited to operational need, controlled exports, protected backups with documented rotation, and request-based deletion support. Payment-card data is not collected in current access-request or provisioning flows.
These are baseline controls, not a guarantee that every preview environment or legacy deployment already meets each item. A customer evaluating production use should request the current deployment checklist and any exceptions in writing.
Use the recorded support form, select “Security concern,” and start the message with [SECURITY]. Include:
For active account compromise, also write “URGENT ACCOUNT SECURITY” in the subject, sign out affected sessions when possible, rotate exposed keys, and tell us which credentials may be involved. Do not send secrets in the report.
We welcome responsible, low-impact reports. There is no paid bug-bounty program or guaranteed reward. To remain within this good-faith policy:
If research follows these rules and is intended to improve security, Biznomad will not initiate legal action based solely on that research. This statement cannot authorize conduct prohibited by another party or applicable law.
Response times depend on severity, available contact information, and whether the report can be reproduced. The Support page lists operational response targets; they are targets, not a service-level agreement.
For architecture questionnaires, processor details, current control evidence, or a security addendum, use the recorded support form and select “Security concern.” Do not rely on an old copy of this page for a procurement decision; ask for the current production scope. No public email fallback is available; each signed closed-beta launch record must name a tested, staffed out-of-band contact.