Security & sub-processors
Dedicated by design
- One dedicated deployment per customer (a program, line of business or facility): its own application instance, its own database connection and its own PostgreSQL database, hosted in the United States. No customer data shares a database with another customer.
Access control
- Named user accounts with salted PBKDF2-SHA256 password hashes; accounts lock for 15 minutes after five failed sign-ins, and temporary passwords must be changed at first sign-in.
- Server-side sessions that can be revoked by the user ("sign out everywhere") or by disabling the account; sessions end after 12 hours idle or 7 days.
- Role-based access (administrator, user), enforced on the server for every action.
Audit and accountability
- Every change is written to an audit log with the acting user. The database itself rejects any update, deletion or truncation of that log, each entry is linked to the previous one by a SHA-256 hash chain, and administrators can export it as a CSV sealed with an Ed25519 signature that an auditor can verify offline with a standalone verifier.
Network and application security
- TLS for all traffic; HTTP Strict Transport Security; a nonce-based Content Security Policy; DDoS protection; rate limiting on sign-in, public endpoints and integration webhooks.
- Integration webhooks authenticate with per-integration API keys: scoped to specific actions, optionally expiring, revocable, shown once and stored only as a hash.
Change management and recovery
- Automated tests (run against the same database engine as production), secret scanning and dependency vulnerability scanning run on every change; each release goes to a staging environment and passes health checks before production, and any release can be rolled back in one step.
- Point-in-time database recovery covering the previous 7 days.
On the roadmap
- FedRAMP authorization and support for agency Authority to Operate (ATO) packages
- Single sign-on (SAML/OIDC), including PIV/CAC sign-in
- Multi-factor authentication
- SOC 2 attestation and independent penetration testing
- Customer-selectable data regions and off-provider backup copies
- Memory-hard password hashing (Argon2id)
Sub-processors
| Provider | Purpose | Location |
|---|---|---|
| Cloudflare, Inc. | Application hosting (Workers), database connection pooling (Hyperdrive), DNS, TLS termination, DDoS protection, logs | Global edge network |
| Neon, Inc. | Managed PostgreSQL database (customer data at rest, point-in-time recovery) | United States (AWS US East, N. Virginia) |
| GitHub, Inc. | Source code hosting and deployment automation (no customer data) | United States |
Reporting a vulnerability
Email briefings@lifecycledashboard.com with "Security report" in the subject. We acknowledge reports within 3 business days. Please do not test against deployments that are not yours. Machine-readable contact: /.well-known/security.txt.