ThreatFade documents its engineering controls and explicitly separates repository implementation from independent assurance. The web platform follows the same standard.
Bounded request and PCAP inputs, finite-number validation and safe temporary PCAP handling.
Rate limiting, request IDs, restrictive CORS and security headers.
Non-root containers, dropped Linux capabilities and no-new-privileges controls.
OIDC/JWT validation with issuer, audience, JWKS and time-claim validation.
Tenant-scoped detection persistence, RBAC and cross-tenant access denied by default.
Dependabot, CodeQL, Gitleaks, pip-audit, SBOM generation and build provenance.
Tests, benchmarks, controls and documented validation are inspectable in the source repository.
Published validation is explicitly scoped; it is not presented as a universal accuracy guarantee.
Certifications, independent testing, contractual SLAs and customer-scale guarantees require separate evidence.
The project does not self-certify SOC 2 or ISO 27001, independent penetration testing, independent detection validation, contractual SLAs, customer-scale performance guarantees, data-residency commitments or organization-level incident-response obligations. Those require separate evidence, controls, contracts or independent assessment.