Security
hardened
admin
demo data
Admin is the highest-value target in this productIt is on its own subdomain,
behind an IP allowlist, with mandatory two-factor and a 30-minute session. Every control on every admin
page writes an audit entry that cannot be edited afterwards.
Admins
2
both 2FA enforced
Allowlisted IPs
3
Session timeout
30min
Last key rotation
11days ago
Controls in force
| Admin subdomain, separate origin | on |
| IP allowlist at the edge | 3 addresses |
| Mandatory TOTP for every admin | enforced |
| Typed reason on destructive actions | on |
| Impersonation notifies the customer | on |
| Impersonation is read-only | on |
| Audit log append-only, hash-chained | on |
| Secrets in vault, never in the repo | on |
| Quarterly credential rotation | scheduled |
| Nightly encrypted backup, restore tested | weekly test |
Break-glass procedure
read before using
- Freeze first, investigate second. A frozen license can be unfrozen in one click; a drained account cannot be refilled.
- Rotate the signing key. Connectors accept both old and new for 24 hours, so nobody is stranded.
- Revoke every session and API key for the affected customer.
- Pull the audit trail for the window and export it before anything else changes.
- Email the affected customers with what happened, what you did, and what they should do.
- Write the incident up publicly, including the parts that went badly.
Admin activity
today 09:12
Signed in
yesterday 16:40
License 7c2eā¦41ab frozen
yesterday 14:02
Refund issued, INV-2026-0790
3 days ago 02:18
Blocked admin sign-in attempt
11 days ago 20:30
Signing key rotated