Security

Network diagrams are a map of your infrastructure. Here is what protects them, and how to tell us if you find a gap.

Reporting a vulnerability

Email security@apexdiagram.com. We acknowledge within two business days and credit reporters who want it. Test only against organisations you own, do not degrade the service, and give us 90 days or a shipped fix before disclosing. The machine-readable policy is at /.well-known/security.txt.

Tenant isolation

  • Every query is scoped to your organisation. Team and MSP organisations run in their own database.
  • Identifying fields (hostnames, addresses, serials, descriptions, documentation, attachments, version snapshots) are encrypted at the application layer with a key per organisation, so a database dump does not expose them. Deleting an organisation destroys its keys first.
  • Customer-managed keys are supported through the key provider interface.

Access

  • Roles: viewer, editor, admin, owner. Change approval can require an admin to review edits before they land.
  • Two-factor authentication (TOTP with recovery codes); required for admins and owners, and optionally for everyone in an organisation.
  • Server-side sessions with idle and absolute limits, per-device sign-out, and lockout after repeated failed sign-ins. Passwords are checked against known breaches.
  • API keys with roles, expiry and IP allowlists, rate limited per key. Share links are stored hashed, expire by default, and can carry a password.

Accountability

  • An append-only audit trail records who changed what, including changes made through the API. Rows are hash-chained so tampering is detectable, exportable to your SIEM, and the database role the application uses cannot alter them.
  • Security events (lockouts, privilege changes, malware detections) raise alerts to an on-call channel.

Software supply chain

  • Every change runs type checks, tests, dependency audit, secret scanning, static analysis and a container vulnerability scan before merge.
  • Releases are container images signed with Sigstore, with a CycloneDX software bill of materials and build provenance attached.
  • Uploaded files are scanned for malware before they are stored, and uploaded SVG symbols are sanitised.

Resilience

  • Encrypted backups of every database under a separate key, with a scheduled restore drill that proves they restore.
  • Recovery objectives and the incident process are documented and rehearsed; see the business continuity and incident response plans in the repository documentation.

Compliance

The controls above are built to the SOC 2 Trust Services Criteria and mapped to ISO 27001 and NIST SP 800-53. Attestation status will be published here as it is achieved.