Security

How ProvenClosed treats your estate and your data.

A tool that looks at your infrastructure should be the least risky thing that does. This page says what ProvenClosed does, what it never does, and what it does not claim — in plain words, so your security team can check each one.

Your estate

  • Nothing is sent to a domain you have not proved you own. Proof is a DNS TXT record. Before it, ProvenClosed builds a passive baseline from public records only. The proof expires and is re-checked, because domains change hands.
  • It observes; it never changes anything. There is no agent to install and nothing is written to your systems.
  • Private and internal addresses are refused, even when a public name points at them — and that is checked again at the moment of each probe, not only when the host was discovered.
  • You choose when active scans run. A scan window in your own time zone keeps probes off production at the hours you name.
  • What it sends is fixed and reviewed. Ports come from a fixed list, and vulnerability checks from 100 hand-reviewed templates pinned to one commit — nothing is downloaded fresh on the morning of a scan.

Your cloud account

  • No access key is stored. You create a read-only IAM role that trusts ProvenClosed's identity through OIDC. ProvenClosed assumes it only when it reads, with credentials that expire within the hour.
  • Read-only, permanently. The policy it asks for lists every call it makes — at most fifteen, all reads, and the extra ones only if you opt in to what they answer. ProvenClosed has no write access to your cloud and is not designed to acquire any.
  • You can end it in one step. Delete the role and ProvenClosed can no longer read anything.

Your data

  • Stored in India — AWS Mumbai (ap-south-1).
  • Isolated beneath the application. Every tenant's rows are fenced by Postgres row-level security, and the application connects as a role that cannot bypass it — so a query that forgets its tenant filter still cannot read another customer's rows.
  • Secrets are encrypted by the application — MFA seeds and integration tokens are sealed with AES-GCM under a key that exists only in production.
  • Backed up every night, and restored every week. Backups are encrypted, versioned and kept off the server; every Sunday the newest copy is fetched back and restored into a scratch database, and every table's row count is compared.
  • Logs keep only where a request went. Outgoing requests are logged by host alone, never with the query strings that would carry your account's identifiers.

Access to your account

  • Multi-factor authentication with any authenticator app.
  • Roles for your team, enforced by the API, not by the screen.
  • Sessions revoked on the server when you sign out — not left to expire.
  • API keys that are read-only, scoped and expiring.
  • An audit log of every sign-in and change, hash-linked so that an edited entry breaks the chain.

The scanners

  • Pinned by digest, and public. Every scanner image is recorded by its registry digest and can be pulled by anyone, so the exact scanner behind a result can be inspected and re-run. The upstream release each image is built from is checked against a pinned checksum.
  • Sandboxed. Each run is a fresh container as an unprivileged user, with every Linux capability dropped, a read-only filesystem, memory and process limits, and a network with no route to ProvenClosed's own systems.

The certificates

  • Signed as DSSE envelopes. The public key set is published at /.well-known/vexora-attestation-keys.json, and verify.py checks a certificate on the reader's own machine. How to verify one.
  • A certificate states what it could not establish, and its state is downgraded rather than rounded up.
  • Each production certificate's fingerprint — a SHA-256 hash, and nothing about the estate — is recorded in Sigstore's public transparency log, and the log's proof travels in the certificate. The verifier checks it offline and refuses a certificate whose issue time does not match when it was logged. Certificates issued before logging began are v0.1-alpha, and the verifier says so.
  • The verifier trusts one issuer, https://provenclosed.com, and takes the key set from there — never from the certificate it is checking.

What ProvenClosed does not claim

  • It is not a CERT-In empanelled auditor, and its certificates are not VAPT certificates.
  • A check is evidence a control owner can cite, not an assessment — it never says a control is met.
  • ProvenClosed does not yet hold its own SOC 2 report or ISO 27001 certificate.
  • A certificate proves what was observed and when. It does not prove an estate is secure, and it says nothing about any moment after its dates.

Reporting a vulnerability

If you find a security problem in ProvenClosed, write to security@provenclosed.com. Please give us a chance to fix it before telling anyone else, and do not access data that is not yours while you look.

See what you expose.
Prove it when it's closed.