SEC-IDENTITY-001
Status: Partly in place
Multi-factor authentication
The current Nightworks AI GitHub organization member list contains no account reported as 2FA-disabled. Organization-wide enforcement is off.
Current Google Workspace organization-wide multi-factor authentication enforcement was not verified.
This checks members individually; it does not mean two-factor authentication is required across the organization.
SEC-TRANSIT-001
Status: Current observation
Encryption in transit
On 31 August 2026, the nightworks.ai Cloudflare zone reported SSL/TLS mode Full with automatic mode enabled.
Full differs from Full (strict). Automatic mode can change the setting, so this records what was observed on that date.
This setting alone does not establish end-to-end encryption, origin-certificate validation, or HSTS, and it may change.
SEC-REST-001
Status: Checked 31 August 2026
Current runtime host
The observed live tenant store persists records in local SQLite and append-only files on one runtime host.
The macOS Data volume on that host reported FileVault enabled on 31 August 2026.
This check covers the host storage volume on that date, not encryption within each application or on other hosts.
SEC-REVIEW-001
Status: Partly in place
Change review
The policy for this public-site repository requires non-author counsel and explicit owner approval for public-claims changes.
For this public-site repository, GitHub branch rules require a pull request and the named lint-test-build, secret-scan, and Cloudflare Pages checks, but currently require zero approving reviews.
Repository policy requires review beyond the platform-enforced minimum.
SEC-IR-001
Status: In preparation
Incident response
Incident response: In preparation.
SEC-ASSURANCE-001
Status: Not asserted
Independent assurance
Security assessment and penetration-test results are not provided here.
This site does not publish a security incident inbox. Do not send credentials, secrets, confidential records, or incident details to the general mailbox.
These limited checks are not a broad security guarantee.