Security

Security that lives
in the structure.

Fibric's control model sits between a base model and an operational system. In the live BearScope path, tenant scope is enforced directly in the application and database. Managed early-access actions are bounded by the capabilities and recovery options each connected system actually supports.

BearScope tenant scope Encrypted in transit and at rest Fail-closed objective Supported action records
How your data is protected

Tenant scope at the live data boundary.

BearScope sets tenant context before governed queries and uses row-level controls on supported tenant-owned tables. This is a concrete live boundary, not a claim that every future service inherits identical enforcement.

Tenant isolation

The live application sets tenant context before governed queries run, and row-level security limits tenant-owned tables at the data layer. We test this as an authorization boundary, not as a display filter.

Encrypted on supported production paths

Current BearScope production data is encrypted in transit with TLS and at rest using managed AWS controls. Supported integration secrets are stored through approved secret-management paths; policy prohibits committing them to code or exposing them through application records, and each connector's logging boundary must be validated.

Source-tagged data

Live BearScope surfaces distinguish governed source data from fallback and missing states. Managed operators must define the minimum context each capability needs and verify that seed or mock values cannot masquerade as customer facts on that path.

Access and identity

Supported actions can be attributed.

Current identity and records are described by product path. Governed BearScope access and supported managed actions preserve attribution where instrumented; no universal record of all reads or downstream effects is claimed.

Authentication

Live BearScope sign-in runs on a managed identity provider. SSO, SAML, directory lifecycle, and provisioning are available only when specified and validated in a written enterprise scope.

Least privilege

The reference architecture maps a capability to a connector through indirection. Managed deployments scope grants to enabled systems and validate the resulting permissions at each connector boundary.

Attributable by default

Supported execution paths record who requested an action, what was proposed, what policy allowed, and what the connected system reported. Reversal means a separate compensating action where that system supports one.

How we build and run it

Risk controls for real-world actions.

The generalized platform is a reference architecture for managed early access. Each enabled action path must validate policy, approval, concurrency, downstream behavior, and recovery; no design label alone makes a physical-system action safe.

Fail-closed

It stops rather than guess

The reference policy objective is to withhold dispatch or request review when an enabled step cannot meet its configured evidence and policy threshold. That behavior must be tested for each managed path.

Duplicate-risk reduction

Single-flight and idempotency controls

Single-flight limits concurrent work per entity, and idempotency keys collapse known retries. Those controls reduce duplicate-action risk; downstream APIs remain part of the end-to-end behavior.

Build pipeline

Reviewed, scanned, watched

Changes are reviewed before they ship. Dependencies are tracked and patched, and the running system is monitored, with enough of a trail to reconstruct what happened.

Compliance and data handling

Stated plainly, including what is still in progress.

We would rather tell you where we are than imply a badge we have not earned.

SOC 2

A Type II program is underway. We will share the report under NDA once it is available, and our control set is built toward it now.

In progress

GDPR and the DPA

Where a customer agreement incorporates our DPA, Fibric acts as a processor for the processing scope identified there. Read the public DPA form.

Contract-specific

Subprocessors

We publish a provider-category summary. The named providers, regions, and change process for a customer are set out in the applicable agreement or schedule. See the public summary.

Public summary

Data residency

Where your data runs, and the regions available, are set out on the availability page. View availability.

US first

Export and deletion

Export, return, deletion, backup-cycle, and confirmation obligations are defined by the applicable customer agreement and incorporated DPA.

Contract-specific
Report a vulnerability

Found something? Tell us.

We welcome reports from security researchers and treat them with priority. Tell us in good faith, and we will work the issue and keep you posted. Read the rules of engagement before you start.

Security contact
security@fibric.io

Use this for vulnerability reports and security questions. For governance and AI transparency, see the trust page. For account help, contact support.

Security protects the system. Governance decides what it may do.

This page is the first half. For how the model is held to a plan, how actions are checked before dispatch, and what happens when trust breaks, read the governance side.