Security
Network diagrams are a map of your infrastructure. Here is what protects them, and how to tell us if you find a gap.
Reporting a vulnerability
Email security@apexdiagram.com. We acknowledge within two business days and credit reporters who want it. Test only against organisations you own, do not degrade the service, and give us 90 days or a shipped fix before disclosing. The machine-readable policy is at /.well-known/security.txt.
Tenant isolation
- Every query is scoped to your organisation. Team and MSP organisations run in their own database.
- Identifying fields (hostnames, addresses, serials, descriptions, documentation, attachments, version snapshots) are encrypted at the application layer with a key per organisation, so a database dump does not expose them. Deleting an organisation destroys its keys first.
- Customer-managed keys are supported through the key provider interface.
Access
- Roles: viewer, editor, admin, owner. Change approval can require an admin to review edits before they land.
- Two-factor authentication (TOTP with recovery codes); required for admins and owners, and optionally for everyone in an organisation.
- Server-side sessions with idle and absolute limits, per-device sign-out, and lockout after repeated failed sign-ins. Passwords are checked against known breaches.
- API keys with roles, expiry and IP allowlists, rate limited per key. Share links are stored hashed, expire by default, and can carry a password.
Accountability
- An append-only audit trail records who changed what, including changes made through the API. Rows are hash-chained so tampering is detectable, exportable to your SIEM, and the database role the application uses cannot alter them.
- Security events (lockouts, privilege changes, malware detections) raise alerts to an on-call channel.
Software supply chain
- Every change runs type checks, tests, dependency audit, secret scanning, static analysis and a container vulnerability scan before merge.
- Releases are container images signed with Sigstore, with a CycloneDX software bill of materials and build provenance attached.
- Uploaded files are scanned for malware before they are stored, and uploaded SVG symbols are sanitised.
Resilience
- Encrypted backups of every database under a separate key, with a scheduled restore drill that proves they restore.
- Recovery objectives and the incident process are documented and rehearsed; see the business continuity and incident response plans in the repository documentation.
Compliance
The controls above are built to the SOC 2 Trust Services Criteria and mapped to ISO 27001 and NIST SP 800-53. Attestation status will be published here as it is achieved.