Security

Built by an offensive team, secured like one.

Cairn holds the most sensitive data an offensive team produces: client evidence, findings, and PII. Security isn’t a page we bolted on. It’s the reason the platform runs on-prem when a contract demands it.

TLS A+ · post-quantumSSO · MFA · RBACOn-prem · zero egressTamper-evident audit
How we protect it

Defense in depth, edge to evidence.

The controls below are live in the platform today. They apply whether you run Cairn as SaaS or entirely inside your own infrastructure.

Transport & edge

Everything is served over modern, hardened TLS with a full security-header suite.

  • TLS 1.3 with post-quantum X25519MLKEM768 key exchange
  • HSTS (preload), strict CSP with per-request nonces
  • CAA records pinning the issuing CA
  • A+ rated transport configuration

Identity & access

Enterprise sign-in, multi-factor, and least-privilege access throughout.

  • SSO via OIDC and SAML, plus magic-link and password
  • TOTP multi-factor with recovery codes; account lockout
  • Granular RBAC with segregation-of-duties on approvals
  • Per-IP rate limiting and email-enumeration-safe responses

Data protection

Sensitive data is encrypted at rest and isolated per tenant.

  • AES-256-GCM encryption of SMTP, OIDC, and AI credentials
  • Invite, magic-link, and API-key tokens hashed at rest
  • Strict per-organization tenant isolation on every query
  • Scoped API keys and operator personal access tokens

Infrastructure

Locked-down cloud infrastructure with secrets in a managed vault.

  • Secrets in a managed Key Vault via workload identity
  • Only HTTPS and hardened SSH exposed; backend ports filtered
  • Managed Postgres and dedicated evidence blob storage
  • Automated patching plus dependency and image scanning

Auditing & integrity

Actions are logged to a tamper-evident trail, and artifacts are verifiable.

  • Cryptographically chained audit trail with integrity checks
  • Ed25519-signed artifact manifests with per-file SHA-256
  • In-browser, offline manifest verifier, no server needed
  • Split service-to-service secrets between internal and user tokens

AI safety

AI drafting is redaction-first and can run entirely inside your network.

  • Client names, IPs, and hostnames redacted before the model
  • Bring your own provider and key, encrypted per organization
  • Human-in-the-loop review before anything is applied
  • On-prem and air-gapped option with zero data egress
Compliance

Straight about where we are.

Cairn helps you evidence compliance: findings map to ISO 27001, SOC 2, NIST CSF, and PCI-DSS controls, with per-framework appendices in every report. That is a product capability, not a claim that Cairn itself is certified.

Formal third-party attestations are on the path, not yet in hand. We lead on capability and we’re earning the proof. If your procurement needs a security questionnaire or architecture detail today, we’ll answer it directly.

Found something?

Report a vulnerability.

We welcome coordinated disclosure and operate under safe-harbor terms. See scope, how to reach us, and what to expect.

← Back to the platform