Security

Security is the product.

How we build, test, and continuously improve security across the Passcore platform, vulnerability disclosure, cryptographic standards, and certifications.

Contact us Contact security team

Vulnerability disclosure

We operate a coordinated disclosure program. If you discover a vulnerability in Passcore, the platform, APIs, or any associated infrastructure, please report it to Contact us.

We commit to:

  • Acknowledgment of receipt within 24 hours
  • Initial triage and severity assessment within 72 hours
  • Regular progress updates throughout remediation
  • Public credit for researchers who report valid findings, unless anonymity is requested
  • No legal action against researchers acting in good faith

Please do not disclose vulnerabilities publicly until we've had a reasonable opportunity to investigate and remediate, typically 90 days.

Penetration testing

Security testing is conducted continuously by our internal security team across the authentication APIs, admin console, SCIM endpoints, and underlying infrastructure. Attack surface reviews run alongside every significant feature release.

If you are a customer who wants to test your Passcore deployment, contact Contact us to coordinate scope and timing.

Cryptographic standards

All data in transit is protected with TLS 1.3. Data at rest uses AES-256-GCM. JWT signing uses CRYSTALS-Dilithium (ML-DSA-65) in hybrid mode with ECDSA P-384 on post-quantum deployments, and ECDSA P-384 elsewhere. Key material is managed through AWS KMS.

Passwords are hashed with Argon2id: memory=64MB, iterations=3, parallelism=4.

Secure development lifecycle

  • All code changes require peer review before merging
  • Static analysis (go vet, staticcheck, gosec) on every pull request
  • Dependency vulnerability scanning via Dependabot and OSV-Scanner
  • Secret scanning at pre-commit and CI stages
  • All production deployments go through staging with automated integration tests
  • Signed commits required for all contributors

Infrastructure security

  • All production access requires MFA-protected IAM roles with least-privilege permissions
  • VPC with private subnets, no direct public internet access to application servers
  • CloudTrail across all regions with immutable log archival to S3 with Object Lock
  • GuardDuty for threat detection across all AWS accounts
  • Automated patch management for all OS-level dependencies
Certifications
SOC 2 Type II Planned
Type II audit planned. Controls being instrumented.
HIPAA Supported
Access controls and audit trails for PHI workloads. BAA available on request.
ISO 27001 Planned
Target certification. Audit scheduled.
PCI DSS SAQ-A Current
Card data never touches Passcore infrastructure.
GDPR / CCPA Current
DPA available. Regional data residency on Enterprise plans.
Contact
Security team
Contact us
Emergency contact
For critical / actively exploited vulnerabilities: use subject line URGENT for immediate escalation
Security advisories

Subscribe to receive security advisories for Passcore, CVEs, severity assessments, and remediation guidance.

Contact us