Security

Your data. Your organization. No one else's.

PonoInsights is designed around the security requirements of NIST SP 800-171 Rev. 2, the standard for protecting controlled unclassified information.

3.1

Access control

  • Every page and API requires a signed-in session, except a short public allowlist.
  • Each customer is a separate organization. Every query is filtered to it in code, and database keys stop records from referencing another customer.
  • Admin-only actions such as adding keys, branding and triage are enforced on the server.
  • Sessions lock after 15 minutes of inactivity, and a system use notice is shown before sign-in.

3.3

Audit and accountability

  • Key changes, syncs, settings changes, finding reviews and denied attempts are recorded with who, what, when and where.
  • Records are append-only and hash-chained, so tampering is detectable. Admins can verify the chain at any time.

3.5

Identification and authentication

  • Two-step verification is required for every account.
  • Passwords are handled by our identity provider and never reach our servers.

3.8

Media protection

  • Compliance scans keep masked excerpts and keyed fingerprints, never the sensitive value itself.
  • Each organization sets its own retention, and older data is deleted automatically.

3.13

System and communications protection

  • TLS everywhere, with HSTS, a content security policy and no framing by other sites.
  • API keys are encrypted with AES-256-GCM, bound to your organization, and support key rotation.
  • Keys are read-only by design and are never displayed after they are saved.

3.14

System and information integrity

  • All input is validated on the server. Errors shown to users never include internal details.
  • Type checks, linting and a full build gate every change.

A shared responsibility.

NIST SP 800-171 applies to an organization's whole system, including people, policies and physical security, not to a single product. PonoInsights implements the technical controls above and documents how each one is met, so you can include it in your own System Security Plan. Some controls, such as account lockout and password rules, are configured in our identity provider, and others, such as training and incident response, remain with your organization.

Get started