Built by an offensive team, secured like one.
Cairn holds the most sensitive data an offensive team produces: client evidence, findings, and PII. Security isn’t a page we bolted on. It’s the reason the platform runs on-prem when a contract demands it.
Defense in depth, edge to evidence.
The controls below are live in the platform today. They apply whether you run Cairn as SaaS or entirely inside your own infrastructure.
Transport & edge
Everything is served over modern, hardened TLS with a full security-header suite.
- TLS 1.3 with post-quantum X25519MLKEM768 key exchange
- HSTS (preload), strict CSP with per-request nonces
- CAA records pinning the issuing CA
- A+ rated transport configuration
Identity & access
Enterprise sign-in, multi-factor, and least-privilege access throughout.
- SSO via OIDC and SAML, plus magic-link and password
- TOTP multi-factor with recovery codes; account lockout
- Granular RBAC with segregation-of-duties on approvals
- Per-IP rate limiting and email-enumeration-safe responses
Data protection
Sensitive data is encrypted at rest and isolated per tenant.
- AES-256-GCM encryption of SMTP, OIDC, and AI credentials
- Invite, magic-link, and API-key tokens hashed at rest
- Strict per-organization tenant isolation on every query
- Scoped API keys and operator personal access tokens
Infrastructure
Locked-down cloud infrastructure with secrets in a managed vault.
- Secrets in a managed Key Vault via workload identity
- Only HTTPS and hardened SSH exposed; backend ports filtered
- Managed Postgres and dedicated evidence blob storage
- Automated patching plus dependency and image scanning
Auditing & integrity
Actions are logged to a tamper-evident trail, and artifacts are verifiable.
- Cryptographically chained audit trail with integrity checks
- Ed25519-signed artifact manifests with per-file SHA-256
- In-browser, offline manifest verifier, no server needed
- Split service-to-service secrets between internal and user tokens
AI safety
AI drafting is redaction-first and can run entirely inside your network.
- Client names, IPs, and hostnames redacted before the model
- Bring your own provider and key, encrypted per organization
- Human-in-the-loop review before anything is applied
- On-prem and air-gapped option with zero data egress
Straight about where we are.
Cairn helps you evidence compliance: findings map to ISO 27001, SOC 2, NIST CSF, and PCI-DSS controls, with per-framework appendices in every report. That is a product capability, not a claim that Cairn itself is certified.
Formal third-party attestations are on the path, not yet in hand. We lead on capability and we’re earning the proof. If your procurement needs a security questionnaire or architecture detail today, we’ll answer it directly.
Report a vulnerability.
We welcome coordinated disclosure and operate under safe-harbor terms. See scope, how to reach us, and what to expect.
← Back to the platform