Skip to main content
DevKosherEchad Cloud
Choose language : Français

Security

DevKosher security is read in what the server refuses, not in what the screen hides.

Identity

OIDC provider, SCIM, WebAuthn, tokens with closed scopes. A scope that is not held is not asked for: it does not appear.

Authorisation, server-side

The BFF filters a view description before rendering it: a column, a filter or an action whose scope is not held does not appear in the response. An authorisation applied only on the surface is an absent authorisation.

Chained audit

The audit log is append-only and chained: a removed entry breaks the chain, and the break is visible.

Divulgation [fr]

Les modalités de signalement de vulnérabilité sont publiées avec la plateforme, avec un délai de réponse annoncé et tenu. [fr]