Security & trust

Your most sensitive decisions deserve a record you can trust.

When an incident puts your business under pressure, confidence comes from knowing who has access, how decisions are recorded, and what the evidence actually proves.

Built for a considered security review by CISO, CIO, and GRC teams.

A foundation for accountable response

Protect access. Preserve context.
Make review possible.

IR-OS combines managed infrastructure with application controls and portable incident records. Evaluate the controls against your organization's requirements and the scope of your deployment.

01 / ACCESS

Identity and organization boundaries

Supabase authentication and database row-level policies support organization-scoped access. Response roles describe responsibilities; they should not be confused with authorization to access sensitive records.

Review membership, permissions, and offboarding.
02 / INFRASTRUCTURE

Managed application infrastructure

The application runs on Cloudflare Workers, with Supabase providing authentication and data services. Cloudflare security rules and rate-limit configurations support protection at the application edge.

Confirm hosting, retention, backup, and recovery scope.
03 / EVIDENCE

Records built for inspection

The incident ledger retains response context and supports SHA-256 chain checks. Signed exports add an issuer signature that can be examined using the independent verifier.

Verify the export and inspect its format coverage.

Independent verification

Trust the evidence.
Check the record.

Give reviewers a portable artifact they can examine without an IR-OS account. The verifier separates chain integrity from issuer authenticity and identifies unsigned or inconsistent records.

Open the record verifier

Cryptographic verification confirms the covered data and signature. It does not establish that every statement is factually correct, create legal privilege, or guarantee regulatory acceptance or insurance coverage.

  1. Export the incident record

    Review its scope, included evidence, and access classification before sharing the artifact.

  2. Check the chain and signature

    Verify that linked event hashes are consistent and the signature matches the expected issuer key.

  3. Understand what is covered

    Legacy v1 signatures bind the event-chain head and selected metadata. The v2 format covers the complete exported bundle except its signature envelope. Check the schema on your actual export.

  4. Keep the context with the evidence

    Review decisions, owners, source references, and missing information alongside the cryptographic result.

AI with human judgment

Useful assistance.
Accountable decisions.

Use AI to explore response options and prepare working material. Keep your team responsible for reviewing the facts, sources, and actions that follow.

Understand the context

Ask AI can use available organization context and incident-response knowledge. Review which records are available to the assistant and confirm permissions before introducing sensitive material.

Check the recommendation

Inspect cited sources, dates, and applicability. AI output can be incomplete or incorrect; a draft is a starting point for qualified human review.

Review data handling

Confirm AI providers, retention, processing terms, and permitted data classifications during procurement. Keep sensitive legal advice within the counsel-approved workflow.

Read the privacy and subprocessor information

Designed for a serious buying decision

Bring the questions that matter
to your security review.

Align security, technology, and assurance requirements before deployment. Use a shared review to make evidence requests, responsibilities, and acceptance criteria explicit.

CISO

Control the exposure.

Review tenant boundaries, privileged access, administrative actions, logging, vulnerability handling, and AI permissions.

CIO

Validate the operating model.

Confirm hosting dependencies, integration scope, support, backup restoration, export access, and recovery expectations.

HEAD OF GRC

Establish the evidence.

Request applicable contractual terms, subprocessor information, control evidence, retention details, and documented exceptions.

  • IdentityConfirm required SSO, SAML, and SCIM delivery scope in writing. Do not infer availability from a plan name.
  • ResilienceAgree on recovery objectives and request evidence of backup and restoration arrangements.
  • Data handlingConfirm processing locations, retention, deletion, subprocessors, and any required agreement or BAA.
  • AssuranceInfrastructure-provider certifications do not constitute an IR-OS SOC 2 attestation or ISO certification.
Request a security review

Tell us your organization, intended use, required controls, and decision timeline. The link opens your email client.

Clear answers

Security questions, answered.

Does a signed record prove compliance?

No. A signature supports authenticity and integrity of the covered data. Compliance depends on the applicable obligations, the underlying facts, and the actions taken. Review the record with the appropriate legal and assurance specialists.

How are authentication and sessions handled?

IR-OS uses Supabase authentication with application session handling. Confirm the identity configuration, session requirements, offboarding process, and any enterprise identity integration during your security review.

Which standards inform the workflows?

Existing plan options include NIST, ISO/IEC 27035, CISA, SANS PICERL, and the IR-OS Expert template. Framework selection supports planning; it does not confer certification. Review the version and applicability of your selected plan.

NIST SP 800-61 Rev. 3 supersedes Rev. 2. Existing legacy templates should be reviewed against current guidance.

Are regulatory clocks legal filing deadlines?

Planning estimates require confirmation of applicability, the triggering event, and the correct calendar. Record the reviewed obligation, owner, and evidence. For example, SEC Item 1.05 generally uses four business days after a materiality determination, not a fixed 96 hours after discovery.

Read the SEC disclosure guidance.

Where can I review subprocessors and compliance requirements?

Start with the privacy policy and subprocessor information. Request current documentation for your deployment. Confirm required certifications, residency, a BAA, and contractual commitments explicitly; a roadmap item is not a delivered control.

What should we confirm about incident communications?

Agree on your security contacts, escalation route, contractual notification requirements, and follow-up reporting during procurement. Notification obligations depend on the incident and applicable law; one universal reporting deadline does not apply to every customer.

Security is a conversation backed by evidence

Make confidence part
of your evaluation.

Bring your requirements. Examine the workflow. Confirm the controls and commitments your organization needs before deploying.

For vulnerability reports, include reproduction steps and the affected component. Do not include customer records or secrets. Coordinate disclosure and avoid accessing data you do not own or disrupting service.