Product security

Vendor data is
sensitive by default.

CoalDark is designed to protect the records, responses, documents, and decisions that make a vendor risk program useful.

Contact security
COALDARK / TRUST BOUNDARY
01IdentityAuthentication + MFA
02AuthorizationTenant + role checks
03DataEncryption + isolation
04ActivityEvents + review history

Safeguards

Protection at each
decision boundary.

01

Encrypted transport and storage

TLS protects data in transit. AWS-managed encryption protects application data and uploaded vendor documents at rest.

02

Tenant-aware authorization

Every authenticated request is resolved against the active tenant and user membership before tenant-scoped data is returned.

03

Strong authentication

Email, Microsoft and Google SSO, passkeys, TOTP multi-factor authentication, backup codes, and password reset controls are supported.

04

Workspace isolation

Partner and client workspaces retain separate tenant context, tokens, memberships, records, and access decisions.

05

Restricted infrastructure

The database is not publicly accessible. API traffic is routed through managed AWS services with security headers and origin controls.

06

Activity records

Authentication events, platform administration, vendor changes, questionnaire actions, and review decisions are recorded for investigation.

Deployment model

Managed AWS infrastructure. Narrow public surface.

CoalDark uses CloudFront and private S3 origins for static application delivery, API Gateway and Lambda for the application API, and a private PostgreSQL data layer. Public routes are limited to the services required for the active vendor risk product.

BrowserCloudFrontAPI GatewayVRM APIPrivate data

Responsible reporting

Found something?

Send vulnerability details to security@coaldark.com. Include reproduction steps, affected URLs, and potential impact. Do not access or modify data that is not yours.

Report securely