← Security

Vulnerability management

Last updated 2026-09-25. Owner: founder.

1. Status

Control Status
CI pipeline (tests, lint, type check, npm audit) on every push Planned — not configured. No CI workflow exists in the repository yet.
Dependabot (npm + GitHub Actions) Planned — not configured.
GitHub secret scanning and push protection Planned (enable when the repository is on GitHub).
Automated tests for tenant isolation, immutability, tamper detection, rules Yes (src/**/*.test.ts, run locally).
Independent penetration test Planned — before the first live firm, then yearly. Not done.
Security review of the codebase (Prompt 10) In progress.

2. Sources of vulnerabilities we watch

  • Dependencies: npm audit, Dependabot alerts, GitHub advisories.
  • Framework: Next.js, Prisma and Node.js security releases.
  • Providers: security bulletins from AWS, Neon, Netlify, Stripe, Resend, Sentry.
  • Our own code: tests, code review, pen test findings, reports from customers or researchers.

3. CI rules (to be put in .github/workflows/ci.yml)

On every push and pull request:

  1. npm ci
  2. npm run lint and tsc --noEmit
  3. npx vitest run (unit tests, then database tests against a disposable Postgres)
  4. npm audit --audit-level=high --omit=dev — fails the build on any high or critical vulnerability in production dependencies.
  5. Deploys to production happen only from the main branch after CI passes.

Dependabot: weekly for npm and GitHub Actions, security updates immediately.

4. Patch timelines

Measured from when we learn of the issue. "Exploitable" means it can be reached in how CheckTrail uses the component.

Severity Examples Fix or mitigate within
Critical (exploitable) Remote code execution, auth bypass, cross-tenant data access 48 hours (mitigate within 24)
High Exploitable injection, privilege escalation, sensitive data exposure 7 days
Medium Limited-impact issues, hard to exploit 30 days
Low / not reachable Dev-only dependency, code path not used 90 days or next routine update

If a fix is not available, record a mitigation (config change, disabling a feature, WAF rule) and the reason. Exceptions are written down with an expiry date.

Routine updates: all dependencies reviewed and updated at least monthly.

5. Penetration testing

  • Planned: an external web-application pen test covering authentication, session handling, tenant isolation, role/branch authorization, file upload, examiner links, and the cron and webhook endpoints. Before the first live firm; then yearly and after major changes.
  • Budget and vendor: not chosen. Get 2–3 quotes; confirm cost before booking.
  • Findings are fixed per the timelines above; a summary letter is shared with customers on request.

6. Reporting a vulnerability

Email security@ (to be set up). We acknowledge within 2 business days. Please don't access other customers' data or disrupt the service while testing.

7. Records

Keep for at least 3 years: CI results, npm audit output at each release, Dependabot history, pen test reports and remediation evidence, exceptions.