10110010011101001011001101101110101018200.devFrom Enterprise.Systems
Start free

Our own security posture

We sell data security. Here is how we handle yours — stated plainly, the same way our product explains its findings.

Data handling

We read the minimum metadata needed to evaluate posture and flows. Where content inspection is required (Flow Guard), content is processed transiently for classification and is not retained beyond the verdict and its evidence excerpt.

Findings, verdicts, and their evidence are stored encrypted at rest. You can export or delete your workspace data at any time — deletion is a product feature, not a support ticket.

OAuth-only scopes

Connectors authenticate with OAuth or vendor APIs using the narrowest scopes that support the engine you enabled. We list every scope we request and why, per connector, in the docs.

No endpoint agents, no network appliances, no browser extensions. Revoking the OAuth grant severs our access instantly — your kill switch is the identity provider you already control.

Platform security

8200.dev signs in through Google Workspace OAuth — there is no password to steal. Organizations can add enterprise single sign-on (SAML with Okta, Azure AD, Google or OneLogin), enforce multi-factor authentication (TOTP authenticator apps plus one-time backup codes) org-wide, and restrict access to trusted IP ranges (IPv4 and IPv6).

Access inside the product is least-privilege by default: fine-grained custom RBAC built from per-feature permission atoms, session policies (maximum duration, idle timeout and force-logout), and a complete, append-only per-organization audit log you can stream or export to your SIEM as CSV, JSON or CEF.

Every release ships behind a suite of over 2,000 automated tests, i18n parity gates across 13 locales, and a production build gate — the same engineering rigor we expect of the systems we secure.

Detective today, preventive when you grant write access

Because we are agentless and connect through read-scoped OAuth, today we detect and explain a risky permission, data flow, or out-of-policy agent action — but we cannot yet block it at the source. Anywhere the product shows "what would be blocked", it is clearly labeled as a SIMULATION. We never claim live enforcement we do not have.

Live preventive enforcement requires elevated write scopes on the connector plus an explicit per-connector opt-in. When you grant them, "would block" becomes "blocked" with no change to how a verdict is reached — only where it is enforced. The exact scopes and the consent steps are documented before you enable them.

No offensive capabilities

8200.dev contains no exploitation, lateral-movement, or offensive tooling of any kind. The platform observes configurations, evaluates data flows, and enforces policy through the vendor APIs you authorized — nothing else.

Audit logging

Every action the platform takes — every scan, finding, block, and configuration change — is written to an append-only audit log. Business and Enterprise tiers can export it.

Our own admin actions on your workspace are logged in the same trail and are visible to you. We don't have a quiet back door into your data, and we made sure you can verify that.

Reporting a vulnerability

Found something? Write to [email protected]. We aim to acknowledge reports within 48 hours, and we don't gag good-faith researchers.

We follow coordinated disclosure with a 90-day window: we work on a fix from the moment you report, keep you updated, and ask that you hold public disclosure for up to 90 days or until the fix ships, whichever comes first.