Trust Center

We publish existing controls and missing evidence with equal clarity.

Identity, access, proxy security, audit, and data controls in the source project are open to technical review. No certification or assurance claim is published without independent evidence.

Identity and least privilege

Built-in auth, LDAP, Google/OIDC, fixed roles, group membership, scoped access policies, and API-token controls.

Connection and secret boundaries

TLS validation, SSRF and redirect protection, controlled egress, and upstream secrets that are never returned by read responses.

Durable audit trail

Administration actions, package usage, operations, and outbound requests are visible through PostgreSQL-backed log surfaces.

Scope available for technical review

  • Identity providers, role matrix, and access-policy resolution
  • Hosted/proxy/group access and anonymous-use boundaries
  • Proxy TLS, SSRF, redirect, and upstream-credential controls
  • PostgreSQL, filesystem/S3, audit, and operational data flows

Technical evaluation

Evaluate your package flow on Smart Kubaba.

Let’s review your formats, deployment, and security policies together.