SphynxOC combines identity-aware authorization, application-layer encryption, encrypted notification credentials, verified integrations, and independently monitored production infrastructure.
PUBLIC BETA DISCLOSURE · UPDATED SEPTEMBER 12, 202601 / IDENTITY & ACCESS
Authentication is managed; authorization is enforced again by SphynxOC.
Clerk manages sign-in, sessions, invitations, and organization membership. Every protected tenant API validates the signed-in user’s active organization and membership before returning or changing organization data.
Viewer, administrator, and owner capabilities follow least-privilege boundaries. Sensitive owner actions—including organization data-key rotation and ownership transfer—are separately restricted and audited.
02 / TENANT ISOLATION
An active organization is the access boundary.
Watchlists, client dependencies, exposure results, notification routes, and audit records are scoped by organization. Membership in one organization does not grant access to another.
Global administrators operate platform-level health and notification controls. That role does not bypass the active-organization membership checks protecting tenant inventory.
03 / ENCRYPTION
Sensitive inventory receives an additional application-layer barrier.
Client identity, geography, service selection, provider, region, and dependency notes are encrypted with AES-GCM before database storage. Each organization has its own data-encryption key, wrapped by a separately hosted master key.
Notification destination credentials are also encrypted. Cloudflare provides encryption at rest for D1 storage and TLS for data in transit; application-layer encryption keeps protected tenant fields unreadable in ordinary database exports and direct SQL inspection.
04 / OPERATIONS
Production failures are observable and recoverable.
Cloudflare protects and operates the edge runtime, while collector telemetry, application alerts, Slack escalation, and independent Better Stack monitoring expose source or scheduler degradation.
Versioned deployments, separated staging and production environments, database migrations, secret rotation, Worker rollback, and D1 recovery rehearsals support controlled incident response.
05 / REPORTING
Security concerns receive a direct operational path.
Beta participants should report suspected unauthorized access, exposed credentials, or unexpected data visibility immediately through their onboarding contact or the authenticated Support control. Reports are triaged without including sensitive tenant contents in shared notifications.