Security Review Readiness
Inspect deployment boundaries, tenant isolation, authorization paths, credential lifecycle, and evidence before rollout. This page describes the review process and control objectives; it does not claim a certification or a completed third-party assessment.
Structured Review Methodology
The engagement scope follows a four-phase review flow informed by established web and API testing guidance. Exact tests, artifacts, retest terms, and third-party involvement are agreed before work begins.
Reconnaissance & Scoping
- Inventory the modules, interfaces, dependencies, and deployment model in scope
- Map REST, Connect/gRPC, WebSocket, and governed Agent Gateway surfaces where applicable
- Document authentication, authorization, tenant, and trust boundaries
- Agree on safe test environments, data handling, and acceptance criteria
Vulnerability Assessment
- Review public interfaces against relevant OWASP testing guidance
- Exercise tenant isolation and authorization-denial paths
- Check credential lifecycle, validation, replay, and rate-limit behavior
- Assess injection, request forgery, dependency, and unsafe-deserialization risks
Exploitation & Proof-of-Concept
- Use controlled proof-of-concept tests in isolated evaluation tenants
- Verify cross-tenant denial and scoped-credential behavior
- Test retry, budget, expiry, and abuse controls included in the selected modules
- Capture reproducible evidence without accessing real customer data
Reporting & Remediation
- Record findings, severity rationale, affected versions, and remediation owners
- Map remediation guidance to the customer and Launch Rail responsibility boundary
- Define retest scope and timing in the engagement before testing begins
- Separate available evidence from roadmap artifacts and customer-specific controls
Encryption Responsibilities Made Explicit
The customer-owned deployment model keeps cloud-key policy in the customer environment. The review identifies where transport, storage, secret, and credential controls must be configured and verified.
Data at Rest
Data in Transit
Credential & Key Lifecycle
Defense in Depth
Use these categories as a review checklist for the selected modules and deployment. A control is treated as implemented only after its configuration and behavior are verified in the target environment.
Infrastructure
- Review VPC, subnet, ingress, egress, and data-service placement
- Define workload identities and least-privilege cloud roles
- Restrict service-to-service paths to the selected topology
- Keep customer credentials inside the customer deployment environment
- Document backup, restore, logging, and incident responsibilities
- Verify artifact provenance and dependency evidence when delivered
Application
- Exercise validation and authorization at documented API boundaries
- Verify rate and budget controls for the selected interfaces
- Review dependency inventory and update process
- Inspect query construction and unsafe input paths
- Confirm origin, webhook, and integration allowlists
- Test error handling for leakage of tenant or secret context
Access & Identity
- Map human, service, and agent identities separately
- Review session expiry, revocation, and credential recovery paths
- Keep Agent Gateway policies default-deny and tenant scoped
- Require approval for configured high-impact agent mutations
- Verify authorization decisions at the service boundary
- Capture attributable events for supported privileged actions
Vulnerability Disclosure Program
We welcome good-faith vulnerability reports and coordinate privately from receipt through validation, remediation, and any agreed disclosure. Timing depends on the validated scope and impact.
Submit Report
Email security@launch-rail.com with affected versions, impact, and a safe proof of concept. Ask for a protected channel before sending sensitive material.
Confirm Receipt
We establish a private coordination channel, confirm the affected surface, and request any details needed for safe reproduction.
Validate & Triage
We reproduce the issue, assess scope and severity, identify affected versions, and agree on a responsible communication plan.
Remediate & Coordinate
We define remediation and disclosure timing from the validated impact. Researcher credit is provided only with written consent.
In Scope
- Launch Rail-owned public website surfaces
- Documented interfaces for modules included in the engagement
- Authentication and authorization paths selected for review
- Evaluation tenants created for approved testing
- Admin, control-plane, and Agent Gateway surfaces when explicitly in scope
- Licensed source versions named in the review agreement
Out of Scope
- Physical security attacks
- Social engineering of employees
- DDoS or volumetric flood attacks
- Automated scanning without prior approval
- Third-party services and integrations
- Customer-owned self-hosted deployments
Request a Security Review Package
Need material for security, legal, or enterprise procurement review? We will share the currently available architecture, data-flow, responsibility, lifecycle, and evidence documents, and clearly identify any artifact that remains a delivery target.