Trust and reliability
Security at WarnFire
Incident systems carry operationally sensitive information. WarnFire is designed to minimize exposed credentials, isolate tenants, and preserve accountable activity history.
Current safeguards
- Encrypted HTTPS ingress and restricted internal service networking.
- Role-based authorization, tenant-scoped database access, and row-level isolation.
- Hashed access credentials and encrypted provider or device secrets where retrieval is required.
- Durable workflows, idempotency controls, rate limits, and duplicate-delivery protection.
- Correlated security and operational logs designed to avoid recording raw credentials.
- Immutable release images and repeatable database migrations.
Customer responsibilities
Use unique credentials, restrict integration keys to their intended services, promptly revoke exposed keys and devices, limit sensitive data in free-form fields, and maintain accurate responder and escalation configuration.
Report a vulnerability
Email security@warnfire.com with a concise description, affected component, reproduction steps, and impact. Do not include active credentials or access data belonging to another customer. We ask researchers to avoid privacy violations, destructive testing, denial of service, and public disclosure before remediation can be coordinated.
This page describes current engineering practices and is not a certification, warranty, or promise that incidents cannot occur.