Skip to content
Security and trust

Security claims should be as traceable as the operating record.

ServSignal separates implemented application boundaries from provider activation and independent verification. The status of each control matters as much as its design.

Current security posture

Implemented controls are not certification.

The application has deterministic authorization, revision, audit, token, QR, file-state, and AI-proposal boundaries. Provider configuration and external exercises are reported separately. This is an architecture and activation-status summary—not a penetration-test report, certification, or contractual SLA.

Authorization boundary
Implemented
File-provider foundations
Configured · qualification pending
Production AI
Disabled
Provider MFA, SSO, and SCIM
Owner-deferred
Independent pen test and restore drill
Pending
Security architecture

Controls that fail closed at the authoritative boundary.

The browser is a presentation layer. Convex derives identity and tenant context, authorizes the operation and fields, validates the expected revision, and returns a projected result.

01Implemented

Tenant and scope enforcement

Tenant context comes from a verified Clerk organization, scoped API token, or signed internal bridge. Protected calls recheck active membership, explicit denies, resource scope, and field policy.

02Implemented

Sensitive-field separation

Restricted network values and credential references use separate projections and distinct permissions for viewing, editing, export, AI, offline use, and QR resolution.

03Implemented

Revision-bound commands

Material writes carry expected revisions and idempotency keys, enforce deterministic transitions, and append history and audit records inside the authoritative transaction.

04Implemented

Opaque tokens and QR

QR and request tokens use high-entropy opaque values, persist only as hashes, support expiry and revocation, and contain no site, asset, network, or credential data.

05Qualification pending

Private file pipeline

Uploads enter private quarantine and are checked for size, checksum, and detected MIME before a verified GuardDuty result can release them. Renderer qualification and live file contracts remain open gates.

06Disabled in production

Human-reviewed AI

AI can create cited proposals only; it cannot decide readiness, tests, approval, or technical writes. Production AI stays disabled until its guarded evaluation is approved and retained.

Data boundary

What ServSignal does not claim or collect.

Product boundaries are explicit so a workflow record cannot be mistaken for a monitoring, vault, or certification product.

  • Store customer passwords, retrieved vault secrets, private keys, recovery codes, or raw API credentials. Credential records are references and deep links only.
  • Actively scan, configure, monitor, or remotely administer customer devices.
  • Put site, asset, network, or credential details inside QR payloads.
  • Allow AI to decide readiness, tests, approvals, or technical writes. AI is currently disabled in production.
  • Treat repository code as proof of provider availability, configuration, backup recovery, or contractual service levels.
  • Claim penetration-test completion, security certification, regulatory compliance, or a qualified digital signature.
Verification status

Verified evidence and open gates stay separate.

Repository and configured-provider evidence does not substitute for the independent security, scale, and recovery work still required before broad enterprise availability.

Verified evidence

  • Automated unit, authorization, Convex integration, browser, accessibility, dependency, and security-boundary checks are repository gates.
  • Production rejects fake providers and fails closed when required core configuration is missing.
  • Daily staging and production Convex backups, including file storage, have been verified, and the Vercel rollback pair was exercised.
  • Private versioned buckets, KMS and Secrets Manager boundaries, and active GuardDuty protection are configured for staging and production.

Open evidence gates

  • Enable and exercise provider-enforced MFA before strict step-up actions enter the launch surface; SSO and SCIM remain owner-deferred.
  • Qualify the dormant renderer by image digest and complete live file, retention, and Object Lock exercises.
  • Run independent penetration and DAST work, target-scale tests, a destructive restore drill, point-in-time replay, and disaster-recovery exercises.
  • Complete the remaining provider-failure, alert-routing, OAuth sandbox, and live-adapter contract evidence.
90-day Guided Live Wave

Start with one bounded, evidence-backed rollout.

Security-dependent capabilities stay unavailable until their activation gates pass. The current engagement begins with one named rollout and an explicit operating boundary.

Review Guided Live Wave pricing