How we build, test, and continuously improve security across the Passcore platform, vulnerability disclosure, cryptographic standards, and certifications.
We operate a coordinated disclosure program. If you discover a vulnerability in Passcore, the platform, APIs, or any associated infrastructure, please report it to Contact us.
We commit to:
Please do not disclose vulnerabilities publicly until we've had a reasonable opportunity to investigate and remediate, typically 90 days.
Security testing is conducted continuously by our internal security team across the authentication APIs, admin console, SCIM endpoints, and underlying infrastructure. Attack surface reviews run alongside every significant feature release.
If you are a customer who wants to test your Passcore deployment, contact Contact us to coordinate scope and timing.
All data in transit is protected with TLS 1.3. Data at rest uses AES-256-GCM. JWT signing uses CRYSTALS-Dilithium (ML-DSA-65) in hybrid mode with ECDSA P-384 on post-quantum deployments, and ECDSA P-384 elsewhere. Key material is managed through AWS KMS.
Passwords are hashed with Argon2id: memory=64MB, iterations=3, parallelism=4.
Subscribe to receive security advisories for Passcore, CVEs, severity assessments, and remediation guidance.
Contact us