Security

hardened
admin demo data
Admin is the highest-value target in this productIt is on its own subdomain, behind an IP allowlist, with mandatory two-factor and a 30-minute session. Every control on every admin page writes an audit entry that cannot be edited afterwards.
Admins
2
both 2FA enforced
Allowlisted IPs
3
Session timeout
30min
Last key rotation
11days ago
Controls in force
Admin subdomain, separate originon
IP allowlist at the edge3 addresses
Mandatory TOTP for every adminenforced
Typed reason on destructive actionson
Impersonation notifies the customeron
Impersonation is read-onlyon
Audit log append-only, hash-chainedon
Secrets in vault, never in the repoon
Quarterly credential rotationscheduled
Nightly encrypted backup, restore testedweekly test
Break-glass procedure read before using
  1. Freeze first, investigate second. A frozen license can be unfrozen in one click; a drained account cannot be refilled.
  2. Rotate the signing key. Connectors accept both old and new for 24 hours, so nobody is stranded.
  3. Revoke every session and API key for the affected customer.
  4. Pull the audit trail for the window and export it before anything else changes.
  5. Email the affected customers with what happened, what you did, and what they should do.
  6. Write the incident up publicly, including the parts that went badly.
Admin activity
today 09:12 Signed inyou · 49.***.***.18 · allowlisted · 2FA ok
yesterday 16:40 License 7c2e…41ab frozenreason: "9 IPs across 4 countries in 1 h" · owner emailed
yesterday 14:02 Refund issued, INV-2026-0790$39.00 · reason: "broker incompatibility, reported within 7 days"
3 days ago 02:18 Blocked admin sign-in attempt185.***.***.7 · not allowlisted · never reached the password stage
11 days ago 20:30 Signing key rotatedscheduled quarterly rotation · 24 h overlap · zero failed verifications