Skip to content

Legal

Security policy and vulnerability disclosure

How to report a vulnerability to INTYGA, what response times to expect, and the architectural invariants we hold ourselves to.

Reporting a vulnerability

If you find a vulnerability or a potential control failure in INTYGA, report it privately to security@intyga.com. Please do not open a public issue for an undisclosed vulnerability.

StageTarget
Initial acknowledgmentWithin 24 hours
Triage and assessmentWithin 72 hours
Remediation for high or critical severityWithin 7 business days

We will keep you informed through remediation and will credit you publicly if you would like that. We will not pursue legal action against researchers who act in good faith, avoid privacy violations and service degradation, and give us reasonable time to remediate before disclosing.

Architectural invariants

These are enforced at the engine, database, and verifier levels, and are treated as non-negotiable in code review.

  1. No central secret for receipt attestation. Offline verification requires no INTYGA secret; relying parties recompute the canonical payload and verify the human's signature themselves.
  2. Per-action step-up. Mutating administrative and state-changing actions require a per-action passkey or security-key signature, not a session.
  3. Zero-knowledge policy relay. Our servers store only your organization's public key. Policy decryption happens client-side in the operator's browser.
  4. Multi-tenant isolation. Tenant queries run under enforced database row-level security with a non-owner application role.
  5. Privacy minimization. Push notifications contain opaque nonces only — never action descriptions, amounts, document names, or personal data.

Vulnerability management

Dependency auditing runs on every CI build. Critical security patches for dependencies and engine components are deployed within 24 hours of notification. Security-relevant events — credential registration, challenge creation, approvals, denials — emit immutable audit entries.

Certification status