Security, SLA & Compliance
1. Defense-in-Depth Philosophy
The Coderyx security framework enforces layered defense spanning application logic, identity management, edge networking, data persistence, and real-time host telemetry. No single security control acts as a single point of failure.
2. Cryptographic Controls & Data Protection
- Data in Transit: All web traffic, WebSocket channels, API requests, and internal SSO ticket exchanges are protected by 256-bit Transport Layer Security (TLS 1.3) with perfect forward secrecy. Unencrypted HTTP traffic is rejected at edge gateways.
- Data at Rest: Application databases, backups, and user media (including unified avatars and ProtoStudio packages) are encrypted using Advanced Encryption Standard (AES-256).
- Password Storage: User authentication credentials are protected with industry-standard, salted one-way cryptographic hashing algorithms. Cleartext passwords never touch logs or disk storage.
3. Zero-Trust Architecture & Micro-Segmentation
The Coderyx ecosystem separates critical services into distinct, mutually isolated security boundaries:
- Single Sign-On (SSO) Isolation: Authentication tickets generated in Central are cryptographically signed, short-lived (5-minute expiration), single-use, and restricted to authorized product hosts.
- Database Isolation: Production databases for Central, Guard, and LeadFlow ERP reside in separate database schemas with least-privilege service credentials.
- Host Firewalls: All server instances are protected by hardened OS-level firewalls and isolated VPC security groups.
4. Identity Verification & Step-Up Security
Identity integrity is enforced at every platform interaction:
- Mandatory Email Verification: Every user must prove ownership of their registered email address before platform dashboards, product tools, or APIs can be accessed.
- Step-Up Password Confirmation: Sensitive account operations (updating passwords, reconfiguring MFA authenticators, revoking active sessions, and cancelling subscriptions) require re-authentication with current credentials to prevent session hijacking.
- Multi-Factor Authentication (MFA): Native support for RFC 6238 Time-based One-Time Passwords (TOTP) compatible with Google Authenticator, Authy, and hardware tokens.
- Unified Profile Synchronization: Single avatar image upload in Central synchronizes across all products, ensuring transparent user identification in team chats and project collaborators.
5. Coderyx Guard & Autonomous Host Isolation
Coderyx Guard continuously consumes host telemetry from Coderyx endpoint defense agents:
- Rule-Based Auto-Isolation: Hosts exhibiting critical MITRE ATT&CK patterns (brute force, ransomware heuristics, unauthorized privilege escalation) can be automatically quarantined via firewall rules.
- SOC Co-Pilot AI: Security alerts are synthesized in real-time by AI analytical engines to formulate immediate, actionable containment steps for incident response teams.
- Live Response CLI: Authenticated security engineers can execute forensic commands directly on monitored nodes inside Guard without opening insecure SSH ports to the public internet.
6. 99.9% Uptime Service Level Agreement (SLA)
Coderyx commits to a 99.9% monthly uptime availability guarantee for all production tiers. In the event of an unplanned outage, eligible customers receive automatic or claimable billing service credits according to the following schedule:
| Monthly Uptime Percentage | Service Credit Issued |
|---|---|
| 99.0% – 99.89% | 10% credit of monthly subscription fee |
| 95.0% – 98.99% | 25% credit of monthly subscription fee |
| Below 95.0% | 50% credit of monthly subscription fee |
7. Regulatory & Industry Compliance
Coderyx operations are maintained in alignment with global regulatory mandates:
- Nigeria Data Protection Act (NDPA / NDPR): Full compliance with local data sovereignty and user privacy provisions.
- General Data Protection Regulation (GDPR): Comprehensive data subject rights, right to erasure, and strict breach reporting protocols.
- Payment Security: PCI-DSS Level 1 compliance through our tokenized payment gateway partner (Paystack).
8. Coordinated Vulnerability Disclosure
We welcome independent security researchers to audit our public attack surfaces in accordance with our ethical disclosure guidelines. If you discover a potential vulnerability:
Email: security@coderyx.com
PGP Fingerprint:
4A9F B72E 11C8 D035 8824 9F10 7C5E 8A33Please allow up to 48 hours for our SOC team to triage and confirm your report before public disclosure.