Desvy SPP2 PlatformSemantic Evidence Infrastructure

Security model

  • PBKDF2-HMAC-SHA256 password hashing (600,000 iterations), never plaintext.
  • Every organization-scoped query is filtered server-side by organization ID — no cross-tenant read is reachable from the UI or API.
  • Strict Content-Security-Policy: no unsafe-inline, no unsafe-eval, no JavaScript at all on this platform's own web UI.
  • CSRF protection on every browser state-changing request; API requests use token auth instead (see Authentication).
  • API keys and webhook signing secrets are shown once at creation and stored only as a hash.
  • Support staff never have implicit access to your evidence — see the break-glass model in our internal operations documentation (summarized: security/audit/super-admin tiers only, reason required, always audited).
↑