Security at CarbonDex
Trust beneath
the analysis.
CarbonDex is built for environments where the integrity of operational information matters as much as its availability. This page describes our security approach and how to report a vulnerability.
01Security by architecture
Security is addressed in the platform's layers rather than added at the interface. Carbon Mesh is designed for encrypted, traceable communication between endpoints and services. Carbon DB is designed to maintain authenticated records and auditable history.
02Deployment flexibility
CarbonDex is designed for edge and local-infrastructure deployment as well as connected configurations. Placement is scoped to each environment's data sensitivity, connectivity, latency, and operator requirements.
03Data protection
Operational data is handled within the boundaries agreed for each evaluation or deployment. Data flows, access, retention, and isolation requirements are defined and documented before integration begins.
04Edge operations
Local intelligence is designed to keep providing operational context when central connectivity is degraded, and to synchronize when connectivity allows. Edge placement can reduce how much operational data must leave the site.
05Auditability
Trusted operational history is a design goal of the data layer: records that preserve source, time context, and change history, so analysis can be traced back to the evidence behind it.
06Deployment boundaries
Every engagement starts by defining what CarbonDex can read, where it runs, who can access it, and what leaves the environment. Any ability to act on operational equipment is defined explicitly, never assumed.