Security status

Security: evidence before assurance.

CalBrix is in early access. These are observed checks and outstanding validation requirements—not a penetration-test report, security certification or production-readiness sign-off.

Effective date: September 5, 2026·Last reviewed: September 5, 2026
Publisher: Montford Orbis Limited

01.Scope

The public demo is for guided evaluation using synthetic data. Do not upload confidential production records or rely on demo outputs for operational calibration. Customer deployments need their own security and acceptance review. See /readiness.

02.Checks observed

  • Public website and lab pages were accessed over HTTPS. This is not an assessment of every endpoint or cipher configuration.
  • An unauthenticated request to a client-record endpoint returned 401. This does not establish all permissions or tenant boundaries.
  • A password-verified signature on a synthetic record passed its hash check. Independent performer/reviewer authorization and regulatory requirements remain unvalidated.
  • Builds and selected regression tests passed; containers reported healthy at deployment. These are not load tests, vulnerability assessments or uptime guarantees.

03.Audit-history limitation

Selected new entries verified, but ten historical entries still have verification mismatches. The overall history must not be described as fully verified, immutable or audit-validated. Historical records were retained, not silently rehashed to hide discrepancies.

04.Controls not yet substantiated

  • No independent penetration-test attestation, SOC 2 report or ISO 27001 certification is presented as verified.
  • Storage-volume encryption, encrypted offsite backups, automatic retention and scheduled restore tests have not been verified in this readiness review.
  • MFA, SSO, account recovery, organization isolation and independent reviewer permissions need dedicated testing.
  • No complete claim is made for WAF coverage, threat-intelligence feeds, alert coverage, secret rotation, protected branches, signed commits or mandatory CI security scanning.
  • Private, on-premise and air-gapped deployments require separate configuration and validation.

05.Backup and recovery readiness

A pre-change database backup was created and its archive listing checked. A full restore was not rehearsed. No measured recovery-time or recovery-point objective is asserted. Encryption, offsite location, retention, restoration and operating responsibilities must be verified before production use.

06.Production acceptance

Agree and test access control, record integrity, data handling, infrastructure security, recovery, monitoring and incident handling before operational use. Request deployment-specific evidence rather than treating a feature list as proof.

07.Existing rights and agreements

This factual status correction does not waive customer rights or reduce obligations in existing signed agreements, the Terms of Service or the Data Processing Agreement. Where those documents require safeguards not yet evidenced here, implementation and contractual review remain necessary. A contractual requirement is not proof of implementation.

08.Vulnerability disclosure

Report suspected vulnerabilities to philip.montford@calbrixos.com with enough detail to reproduce the issue. Do not access other parties' data or degrade the service. Allow reasonable time for investigation before public disclosure. Good-faith security research conducted in accordance with this policy will not be subject to legal action by Montford Orbis. No fixed response or remediation time is represented as an established service level.

09.User responsibilities

Safeguard credentials, assign appropriate permissions and use synthetic records during evaluation. Do not use unvalidated calculations, AI suggestions, dashboard statuses or demo certificates for safety or compliance decisions. Report suspected misuse or integrity concerns to the founder.

Questions about this document?

This page is published by Montford Orbis Limited in connection with the CalBrix OS service. For clarifications, long-form versions required for procurement or audit review, or to request a signed copy, write to the founder directly.

Report a concern