Security at Chokidar
Built to be trusted with your infra
We are focusing security messaging on launch-ready controls and explicit commitments. We do not over-promise beyond what is being shipped now.
Launch hardening scope
- Prod signing/encryption certificates via env or KMS
- mTLS termination for agent gRPC with internal CA validation
- CSRF protection for cookie-based flows
Baseline controls at launch
- Secret scanning in CI (gitleaks)
- Public `/.well-known/security.txt` with PGP key
- Actionable alerting and audit trails for operational visibility
Issue response commitment
- At launch, we commit to prioritizing and addressing critical and medium issues
- Security changes are rolled out incrementally with clear release notes
- We avoid broad certification promises until controls are fully shipped
Product state clarity
- OIDC SSO is planned as Soon (Pro)
- OTel ingestion and log analytics are planned as Soon (Pro)
- Scalability is a core platform goal, with ongoing hardening by stage
Compliance & certifications
We are sharing practical launch scope now and avoiding broad certification claims. Contact us via [email protected].
Launch hardening scope
Concrete controls listed and tracked for launch readiness
Security issue handling
Critical and medium issues prioritized at launch
Formal certifications
No public certification commitment at this stage
Responsible disclosure
Found a vulnerability? Send us a detailed write-up and we will acknowledge quickly, triage, and prioritize critical and medium issues as part of launch commitments.
Email:[email protected]
PGP key:/.well-known/security.txt
In scope
- · *.chokidar.bd production endpoints
- · Agent binaries and communication protocol
- · Authentication, authorization, tenant isolation
Need to review us deeper?
We will gladly walk procurement and security teams through current controls and launch hardening scope.