TFTHREATFADE
ProductDetectionHow it worksIntegrationsResearchSecurityDocsPlaygroundPricingEnterprise
GitHub
ProductDetectionHow it worksIntegrationsResearchSecurityDocsPlaygroundPricingEnterprise
HomeEnterprise security center

Evidence first. Claims stay bounded by what is actually deployed.

This center separates implemented controls from documented interfaces, on-demand capabilities and items that are deliberately not claimed. It is intended for security architects, procurement teams and technical evaluators.

Identity

OIDC SSO with PKCE/state/nonce validation

implemented

NextAuth OIDC provider and engine enterprise session boundary are present in the web application.

Identity

SAML SSO

on-demand

No SAML provider is represented in the current dependency or provider configuration.

Limitation: Do not market SAML as generally available until a validated enterprise requirement and implementation exist.

Authorization

Organization-scoped RBAC

implemented

Existing authenticated organization/member and analyst boundaries are reused by enterprise workflows.

Governance

Security/audit event contract

documented

Enterprise governance documentation defines required authentication, authorization, administrative-action and access-event fields.

Limitation: The public website does not claim an immutable enterprise audit-log retention service until the backing deployment provides it.

Operations

Health, readiness and version visibility

implemented

Existing health/version engine boundary is exposed through the web integration architecture.

Interoperability

SIEM/SOAR/webhook/STIX integration contract

documented

Enterprise integration contract defines adapter boundaries and supported output formats without inventing live connectors.

Limitation: A connector is only advertised as available after an actual adapter is deployed and tested.

Assurance

Security and procurement evidence center

implemented

Public enterprise security and procurement center provides architecture, control, evidence-status and contact material.

Compliance

Independent certification

not-claimed

No certification is asserted by this release.

Limitation: Certification/compliance status requires the relevant independent assessment or attestation.

Architecture →

Control-plane, detection-plane and deployment boundaries.

Security →

Implemented application-security controls and assurance limits.

Independent assurance →

External-validation evidence and explicit claim boundaries.

Documentation →

Operational and deployment documentation.

Vulnerability disclosure →

Security reporting and responsible disclosure path.

Procurement →

Questionnaire-ready evidence index and contact path.

ThreatFade does not claim SOC 2, ISO 27001, FedRAMP, PCI DSS or other certification from this page. Independent assurance is reported only when the corresponding evidence exists.

THREATFADE / TINLANCE LIMITEDSource on GitHub