Security

Factulabs is built with a security-first workflow. Sensitive fiscal and identity artifacts are protected by design.

Core commitments

  • Secrets are never exposed in API responses, logs, or public documentation.
  • Tenant boundaries are enforced at read/write/delete query level.
  • Certificate and key artifacts are encrypted at rest and handled in bounded runtime paths.
  • Error responses remain sanitized and never expose internal stack traces.

Responsible disclosure

If you discover a vulnerability, please report it to security@factulabs.com.