Security
How we secure ABTDS.
ABTDS is a security product. We hold ourselves to a higher standard than most early-stage SaaS.
- Data residency: your endpoint logs never leave your VPS. We don't aggregate, train on, or mirror customer data.
- Auth: Clerk-backed SSO with invite-only sign-up. No public registration. SAML on Enterprise.
- Transport: TLS 1.3 everywhere. HSTS preload. Strict CSP.
- Disclosure: 90-day coordinated disclosure window. PGP key on request. Bug bounty starts with case study #1.
- Audit log: every triage action stamped with Clerk identity + timestamp. Exportable as JSON.
Report a vulnerability: security@abtds.io