Deployment boundary
Tester runs on infrastructure controlled by the customer. Local execution, reports and configured credentials remain there. External AI providers are disabled until an administrator explicitly configures and allowlists one.
Identity and authorization
Server-side deny-by-default authorization protects organizations, projects and resources. OIDC Authorization Code with PKCE, SAML and SCIM are available for managed deployments. Secrets are write-only through the UI and encrypted at rest.
Release integrity
The public download page pins the published package size, SHA-256 checksum and exact native-signature state. The entitlement release endpoint separately carries the signed manifest, SBOM and support dates. Customers should verify the evidence available for their channel before installation. License signatures are verified offline; support dates never create a runtime kill switch.
Commerce isolation
Paddle collects payment card data. The Alcyone commerce Worker stores only entitlement and audit identifiers in D1, keeps release objects in R2, and queues webhook processing after verifying the raw-body signature and event id.
Incident and vulnerability contact
Report a suspected vulnerability privately to support@alcyone-systems.com with reproduction details but no live credentials. We acknowledge credible reports and coordinate remediation and customer notification based on severity.
Assurance language
Alcyone Systems does not claim that Tester is DORA certified or automatically makes a customer compliant. We provide architecture, SBOM, update, incident and supplier evidence that customers can assess in their own regulatory program.