Identity and access
Customer and administrator access are separated. Administrative capabilities require authenticated identity and role authorization. Negative tests verify denial of unauthenticated, forged, and incorrectly scoped requests.
Protected secrets
Production service secrets are encrypted at rest with operating-system protection and restrictive access controls. Values are excluded from ordinary configuration, reports, and operational evidence.
Service boundaries
Licensing authority, licensing administration, and customer Account Center functions are separated with independent tokens and least-purpose interfaces.
Monitoring and audit
Automated checks monitor service state, listeners, readiness, public availability, retention, and disk thresholds. Administrative mutations include identity, reason, correlation, and idempotency context.
Backup and recovery
Database backups are verified and restored in isolated rehearsals. Protected-secret recovery inventories document encrypted boundaries without exporting plaintext.
Report a concern
Email support@scalovus.com with the affected component, steps, and impact. Do not access other users’ data or disrupt production while testing.
