Security at Sigvex is the public page that describes how the platform itself is secured. It walks the security program end to end — how the application is built and sandboxed, how the infrastructure and data are protected, how activity is monitored, and how to report a problem — in one place a reviewer can read without signing in.
Why it exists
Anyone evaluating Sigvex for procurement needs a single, public statement of its security posture. This page is that document, linked from the footer so a prospective customer or a legal reviewer can find it directly.
Who uses it
- Procurement or legal reviewer — evaluates Sigvex against their security requirements.
- Prospective customer — reads it before signing up.
What’s on the page
The page moves through the security program by area: a statement of commitment; application security (secure development, input validation and sandboxing, browser-based fuzzing); infrastructure security (hosting and network, access controls); data protection (encryption and data handling); monitoring and incident response; third-party security and vendor review; responsible disclosure; and how to contact the security team.
Limits
- It’s a public, read-only page — no sign-in required.
- Feedback on the security posture, or a vulnerability report, goes through the responsible-disclosure flow rather than this page.
Related pages
- Responsible Disclosure — how to report a platform vulnerability.
- Forensic Provenance Ledger — the tamper-evident audit trail.