01
Server-side client credentials
The BFF reads the KernelCore client identifier and API key from server environment variables and adds them upstream. They are not exposed as public browser configuration.
Trust Center
YowSpare treats security as an operating discipline across identity, organization context, permissions, service integration, deployment, and customer-controlled devices. This page separates controls visible in the current system from deployment responsibilities and future assurance work.
Security posture
The statements below are based on controls present in the YowSpare frontend, its backend-for-frontend layer, and the connected enterprise core-services platform. Availability, retention, encryption at rest, backup, and certification commitments apply only when confirmed for a deployment or in a signed agreement.
Implemented controls
These safeguards reduce risk, but none removes the need for secure deployment, correct customer configuration, monitoring, and disciplined user behavior.
01
The BFF reads the KernelCore client identifier and API key from server environment variables and adds them upstream. They are not exposed as public browser configuration.
02
KernelCore API routes require authenticated requests and apply client-application and organization-service entitlement filters before protected operations proceed.
03
Tenant, organization, and agency context accompany business requests. Backend policies evaluate user context and permissions for protected administrative and operational actions.
04
YowSpare distinguishes read and write authorities in the interface while backend permission policies remain the authoritative security boundary.
05
The sign-in flow supports MFA challenges and enrollment where required by the account or privileged-user policy. Availability depends on backend and tenant configuration.
06
Public health and information checks are separated from protected management endpoints, which require dedicated management authority and a configured strong key.
07
The backend provides a configurable CORS allowlist and credential policy. Production deployments must restrict allowed origins to approved YowSpare domains.
08
The service exposes request identifiers for troubleshooting, and the BFF avoids caching upstream API responses by default to reduce stale sensitive responses.
Control matrix
Security depends on application code, deployment configuration, customer administration, and endpoint hygiene. The matrix makes those boundaries explicit.
| Area | Current position | Primary owner |
|---|---|---|
| Identity and MFA | Password authentication and MFA flows are supported. Enforcement and recovery behavior depend on account and backend configuration. | YowSpare and core platform |
| Authorization | Read and write permissions, administrative policies, and service entitlements are evaluated using authenticated business context. | YowSpare, core platform, and customer admin |
| Client application secrets | Client credentials are held by the server-side BFF. Secure environment injection and rotation remain deployment responsibilities. | YowSpare operations and deployment owner |
| Transport security | The deployed API uses HTTPS and the gateway supports TLS when configured. Certificates, allowed protocols, and termination must be verified per environment. | Deployment owner |
| Browser and offline data | The web client currently stores the session token, selected business context, preferences, drafts, and caches locally. Device compromise can expose local data. | YowSpare and customer endpoint owner |
| Data at rest and backups | Database encryption, volume protection, backup frequency, retention, restoration, and regional redundancy depend on the deployed infrastructure and contract. | Deployment owner |
| Logging and audit | Application and business audit capabilities exist, but immutability, export coverage, and retention must be validated for the selected services and plan. | YowSpare, core platform, and customer |
| Assurance and certification | YowSpare does not currently claim ISO 27001, SOC 2 Type II, or another independent security certification on this page. | YowSpare leadership |
Shared responsibility
The platform can enforce only the controls that are correctly deployed, configured, and used. Customers should define internal ownership before production rollout.
Deployment baseline
A production deployment should not be approved solely because the application builds successfully. The operating environment must meet a documented baseline.
The current web application stores its bearer session token and selected tenant, organization, and agency identifiers in browser local storage. It can also retain operational drafts and cached resources for selected offline and progressive-web behavior. This improves continuity but increases the importance of endpoint security.
Assurance
Security language must remain verifiable. YowSpare will publish certification, penetration-test, uptime, backup, and recovery claims only after the relevant scope, evidence, ownership, and renewal process are established.
Designing toward recognized practices is not the same as holding ISO 27001, SOC 2, or another independent attestation.
Availability, support, maintenance, and service-credit commitments apply only when stated in an Order Form or service-level agreement.
Tenant and organization controls reduce cross-context access risk, but security depends on implementation, configuration, testing, and operations.
Audit, backup, and customer-data retention vary by service, legal need, customer configuration, and contractual commitment.
The following areas are priorities for structured hardening and assurance. They are not presented as completed controls.
Incident response
A security signal becomes actionable only when ownership, evidence, containment, recovery, and communication are coordinated. Deployment-specific response times and notification commitments apply only when documented in the applicable agreement.
01
Validate the signal, determine affected services and organizations, classify severity, and preserve relevant request, access, and system evidence.
02
Limit exposure, isolate affected components, revoke compromised credentials or sessions, and restrict integrations when reasonably necessary.
03
Remove the cause, deploy verified remediation, restore trusted operation, reconcile affected records, and monitor for recurrence.
04
Inform affected parties where law or contract requires it, document decisions and impact, and convert lessons into tracked control improvements.
Responsible disclosure
Send a concise description of the affected component, reproduction steps, potential impact, timestamp, and request ID. Remove personal data, credentials, and confidential customer records from the report whenever possible.
tdjotio@gmail.com
Related trust documents