VC-TR-002 / 8 MIN / 09 AUG 2026

Public security overview

Product state, security principles, threat boundaries and current assurance state in a reviewable overview.

State: controlled MVP · not externally audited
MaturityCurrent product state
Review basisRepository-aligned
Reviewed2026-08-09
01

Product and review state

VENTEX Connect is operated as a controlled MVP. The documented delivery includes a web application, installable PWA and API-first architecture.

This overview is a technical product description. It is neither a certification nor an external audit report and does not claim equivalence with classified communication systems.

  • Controlled MVP rather than general availability
  • Web, PWA and API-first delivery
  • No external security certification
  • No absolute security claim
02

Public security principles

Devices, sessions and revocation are visible security objects. Protected messages and attachments are processed on authorised endpoints; the service is designed not to treat content as conveniently usable plaintext.

Public claims are limited to the maturity supported by repository evidence, tests or approved runtime evidence.

  • Devices as a controllable boundary
  • Content protection before transport trust
  • Evidence before claims
  • Explicit separation of active, pilot and planned
03

Threats and boundaries

The current model considers stolen credentials, lost devices, unauthorised API calls, compromised transport and an inquisitive service operator.

A fully compromised endpoint, coerced use, hardware side channels and unknown platform flaws remain outside the claimed protection boundary.

04

Assurance roadmap

Automated quality gates, browser checks and release records reduce defects but do not replace independent review.

High-security, government or certification claims require a scoped architecture review, penetration test and independent cryptography audit.