Loading...
The guardian opens the doors.
Loading...
The guardian opens the doors.
Security is foundational to Dayus Corp. The platform is engineered for regulated and privacy-conscious customers, with defence-in-depth controls across the stack.
TLS 1.3 in transit. AES-256 at rest. Per-tenant key rotation with HSM/KMS-ready envelope encryption.
Role-based access with 7 distinct roles, mandatory 2FA for privileged operations, and per-resource authorization checks.
Mandatory peer review, static analysis (CodeQL, ESLint security rules), dependency scanning, and continuous secret scanning on every commit.
Append-only audit log for sensitive actions: authentication events, role changes, data exports, and admin operations. Logs retained for 365 days.
On-call rotation with documented runbooks. SLA: acknowledgement within 15 minutes for security incidents. Post-mortems shared with affected customers within 5 business days.
GDPR-ready data subject workflows. Every sensitive action is anchored in an append-only, tamper-evident audit chain — run scripts/verify.py yourself against our published verification key. Sub-processor list available on request.
We welcome coordinated disclosure from security researchers. Email security@dayuscorp.com with reproduction steps. We acknowledge within 1 business day and commit to a remediation timeline within 5 business days.