Transport and storage
Production deployments should use HTTPS. Sensitive connection material is kept out of public pages, source repositories, and user-facing reports. Stored data should be protected using access controls appropriate to its sensitivity.
Access control
Administrative and business access is limited by role and business need. Permissions should follow the principle of least privilege.
Operational safeguards
- Logging of relevant connection and administrative events.
- Dependency and configuration review.
- Backups and recovery procedures appropriate to the service.
- Prompt revocation or rotation of credentials when risk is identified.
Incident response
Suspected security incidents are investigated and contained. Affected credentials may be revoked, and impacted users or authorities will be notified where required.
Report a concern
Security concerns may be reported to [email protected].
Last updated: August 6, 2026