Trust is not a badge. It is a verification path.
Security architecture, public claims, operational evidence and deliberate boundaries—in one canonical, versioned and directly linkable place.
Six domains. One verifiable language.
Every domain states its current status, technical basis and the boundary of the claim.
Security architecture
Protection layers, cryptographic paths and the boundaries of the current VENTEX Connect product state.
Identity & access
Passwords, passkeys, devices, sessions, invitations and administrative access controls.
Privacy & metadata
Which data Connect needs, which content is protected and where metadata is deliberately reduced.
Operations & resilience
Release controls, health checks, status measurement and the limits of the current single-host operation.
Assurance & boundaries
How VENTEX distinguishes implemented, internally evidenced, limited and planned capabilities.
Responsible disclosure
Report security issues safely, understand scope and enable coordinated handling.
Claim and boundary stay together.
Selected product claims link directly to their full record in the public Evidence Center.
The Double Ratchet is the default send path for known recipient devices; device envelopes and epochs support rotation and multi-device operation.
Direct identifiers have been removed from several stored communication paths or replaced by opaque conversation-scoped references.
Refresh tokens rotate and reuse revokes the affected token family.
Releases can be gated by types, tests, build, migration, smoke checks and signed release evidence.
Maturity is not asserted. It is classified.
- 01
Implemented
Present in the delivered system and traceable in source.
- 02
Internally evidenced
Supported by automated tests or operational evidence.
- 03
Limited
Usable, but only within an explicitly stated boundary.
- 04
External assurance
Audit, penetration test and deployment acceptance remain independent.
