Product and review state
VENTEX Connect is operated as a controlled MVP. The documented delivery includes a web application, installable PWA and API-first architecture.
This overview is a technical product description. It is neither a certification nor an external audit report and does not claim equivalence with classified communication systems.
- Controlled MVP rather than general availability
- Web, PWA and API-first delivery
- No external security certification
- No absolute security claim
Public security principles
Devices, sessions and revocation are visible security objects. Protected messages and attachments are processed on authorised endpoints; the service is designed not to treat content as conveniently usable plaintext.
Public claims are limited to the maturity supported by repository evidence, tests or approved runtime evidence.
- Devices as a controllable boundary
- Content protection before transport trust
- Evidence before claims
- Explicit separation of active, pilot and planned
Threats and boundaries
The current model considers stolen credentials, lost devices, unauthorised API calls, compromised transport and an inquisitive service operator.
A fully compromised endpoint, coerced use, hardware side channels and unknown platform flaws remain outside the claimed protection boundary.
Assurance roadmap
Automated quality gates, browser checks and release records reduce defects but do not replace independent review.
High-security, government or certification claims require a scoped architecture review, penetration test and independent cryptography audit.
