Security readiness

Accurate assurance starts with stating what is—and is not—proven.

EasyAuths is a development preview, not an authorized production service. The repository contains meaningful security controls and tests, but production identity, managed infrastructure and keys, external review, and operational evidence are still required.

Implemented locally

Tenant- and role-scoped service/API boundaries, forced PostgreSQL RLS, transaction-bound web WebAuthn verification, single-winner state transitions, prototype ES256 receipts and JWKS, tamper-evident audit-chain verification, encrypted durable delivery jobs, redacted logs, and automated security/contract/database/browser gates.

Not production evidence

The primary web login is still a demo selector. Managed PostgreSQL recovery, KMS/HSM custody, real mail/push, production sessions, native hardware-backed proof, provider telemetry, staging/DR exercises, independent penetration testing, compliance review, and real-device/assistive-technology matrices are incomplete.

Integrity language

Audit records and local exports are described as tamper-evident, not immutable. A signed receipt is evidence for its exact verified payload and lifecycle—not proof that a person, organization, device, business instruction, or underlying event is legitimate beyond the stated assurance.

Responsible disclosure readiness

No public vulnerability-intake channel, safe-harbor policy, response target, or bounty is approved yet. Do not place secrets, personal data, production credentials, or sensitive reports into the demo. Product, Legal, and Security must approve and staff the disclosure process before a contact address is published.

See release readiness →