Trust
Security at DramAudit
Venue isolation
Organizations, memberships, entitlements, devices, and operational cells have explicit venue identities. Customer queries are scoped on the server; printer agents receive revocable device credentials limited to one venue.
Account protection
Passwords use memory-hard hashing, sessions have idle and absolute expiry, state-changing requests use CSRF protection, and time-based two-factor authentication is available. Administrative and support actions are recorded in immutable audit events.
Support privacy
Fleet status is visible to platform operations. Private conversations require explicit scope and an expiring support-access record.
Reporting
Report security concerns to security@dramaudit.com. Do not include sensitive venue data in the first message.