Security at CarbonDex

Trust beneath
the analysis.

CarbonDex is built for environments where the integrity of operational information matters as much as its availability. This page describes our security approach and how to report a vulnerability.

01

Security by architecture

Security is addressed in the platform's layers rather than added at the interface. Carbon Mesh is designed for encrypted, traceable communication between endpoints and services. Carbon DB is designed to maintain authenticated records and auditable history.

02

Deployment flexibility

CarbonDex is designed for edge and local-infrastructure deployment as well as connected configurations. Placement is scoped to each environment's data sensitivity, connectivity, latency, and operator requirements.

03

Data protection

Operational data is handled within the boundaries agreed for each evaluation or deployment. Data flows, access, retention, and isolation requirements are defined and documented before integration begins.

04

Edge operations

Local intelligence is designed to keep providing operational context when central connectivity is degraded, and to synchronize when connectivity allows. Edge placement can reduce how much operational data must leave the site.

05

Auditability

Trusted operational history is a design goal of the data layer: records that preserve source, time context, and change history, so analysis can be traced back to the evidence behind it.

06

Deployment boundaries

Every engagement starts by defining what CarbonDex can read, where it runs, who can access it, and what leaves the environment. Any ability to act on operational equipment is defined explicitly, never assumed.

SECURITY REVIEWS

Evaluate the controls
as they exist today.

We describe the current implementation plainly.

Organizations evaluating CarbonDex can request architecture documentation and discuss security questionnaires as part of a technical evaluation. Controls, interfaces, and deployment requirements are confirmed for the proposed environment and documented in any separate agreement.

CarbonDex does not represent certifications, authorizations, or attestations it has not obtained. Where a requirement applies to your environment, we will discuss it directly.

Discuss a security review
THIS WEBSITE

The public site.

carbondex.net is served over HTTPS with a restrictive Content Security Policy. It does not host customer telemetry, and its demonstrations run in your browser with illustrative data. See the privacy policy for how contact requests and analytics are handled.

RESPONSIBLE DISCLOSURE

Security
researchers.

If you believe you have identified a security issue involving CarbonDex systems, software, or this website, contact us.

security@carbondex.net

Please include

We ask that you

We acknowledge reports and keep researchers informed as we investigate. Machine-readable contact details are published at /.well-known/security.txt.