Chokidar
Security at Chokidar

Built to be trusted with your infra

We are focusing security messaging on launch-ready controls and explicit commitments. We do not over-promise beyond what is being shipped now.

Launch hardening scope

  • Prod signing/encryption certificates via env or KMS
  • mTLS termination for agent gRPC with internal CA validation
  • CSRF protection for cookie-based flows

Baseline controls at launch

  • Secret scanning in CI (gitleaks)
  • Public `/.well-known/security.txt` with PGP key
  • Actionable alerting and audit trails for operational visibility

Issue response commitment

  • At launch, we commit to prioritizing and addressing critical and medium issues
  • Security changes are rolled out incrementally with clear release notes
  • We avoid broad certification promises until controls are fully shipped

Product state clarity

  • OIDC SSO is planned as Soon (Pro)
  • OTel ingestion and log analytics are planned as Soon (Pro)
  • Scalability is a core platform goal, with ongoing hardening by stage

Compliance & certifications

We are sharing practical launch scope now and avoiding broad certification claims. Contact us via [email protected].

Launch hardening scope
Concrete controls listed and tracked for launch readiness
In progress
Security issue handling
Critical and medium issues prioritized at launch
Committed
Formal certifications
No public certification commitment at this stage
Not announced

Responsible disclosure

Found a vulnerability? Send us a detailed write-up and we will acknowledge quickly, triage, and prioritize critical and medium issues as part of launch commitments.

In scope

  • · *.chokidar.bd production endpoints
  • · Agent binaries and communication protocol
  • · Authentication, authorization, tenant isolation

Need to review us deeper?

We will gladly walk procurement and security teams through current controls and launch hardening scope.