Sekyoor
Security
Last updated July 29, 2026
Almost everything a jurisdiction needs to evaluate is about the platform, not this marketing site. This page is a placeholder for that documentation plus a working route for reporting problems.
Reporting a vulnerability
If you have found a security issue in this site or in the Sekyoor platform, send it toTODO: security contact address. Include enough detail to reproduce it.
We will acknowledge within TODO: acknowledgement window and keep you updated until it is resolved. We will not pursue legal action against anyone who reports a genuine issue in good faith, does not access or modify other people's data, and gives us reasonable time to fix it before disclosing.
TODO: publish /.well-known/security.txt pointing at that address — several state procurement checklists look for it.
This website
- Static files only. No application server, no database, no user accounts.
- No third-party scripts, fonts, or embeds. Everything is served from this origin.
- The only data path is the demo form, which posts to the processor named in the privacy notice.
- TODO: confirm TLS configuration and add security headers at the edge — HSTS, Content-Security-Policy, X-Content-Type-Options, Referrer-Policy. Static hosting means these are set on the CDN, not in application code.
The platform
Everything below is what buyers will ask for, and none of it can be filled in from the marketing site. TODO: answer each item with what is actually true today — an aspirational answer here becomes a contractual representation.
- Hosting model and data residency.
- Tenant isolation.
- Encryption in transit and at rest.
- Authentication, SSO support, and role-based access control.
- Audit logging and how long records are retained.
- Backup, restore, and tested recovery objectives.
- Vulnerability management and patch cadence.
- Subprocessors.
- Incident response and breach notification commitments.
- Independent assurance — SOC 2, StateRAMP, TX-RAMP or equivalent, including whether anything is in progress rather than complete.
- Penetration testing history.
Do not publish this page until every placeholder is replaced. A security page that describes intentions rather than controls is a liability in a procurement file.