Security boundary
Controls designed around tenant-scoped operational evidence.
Security claims are limited to the reviewed product and production controls currently evidenced by NeuralOps Twin.
Implemented controls
- Membership-derived tenant authorization and negative isolation tests.
- HttpOnly, SameSite session cookies with Secure enabled in production.
- Private version-pinned object storage and bounded file processing.
- Malware scanning before parsing and deterministic analytics.
- Environment-controlled secrets with no credentials committed to source.
- HTTPS, restrictive browser headers, sanitized errors, and bounded evidence.
Responsible reporting
Do not send credentials, tokens, customer files, or sensitive evidence by email. Report a suspected security issue to support@neuralshielddigital.com.