Trust

Security at DramAudit

Venue isolation

Organizations, memberships, entitlements, devices, and operational cells have explicit venue identities. Customer queries are scoped on the server; printer agents receive revocable device credentials limited to one venue.

Account protection

Passwords use memory-hard hashing, sessions have idle and absolute expiry, state-changing requests use CSRF protection, and time-based two-factor authentication is available. Administrative and support actions are recorded in immutable audit events.

Support privacy

Fleet status is visible to platform operations. Private conversations require explicit scope and an expiring support-access record.

Reporting

Report security concerns to security@dramaudit.com. Do not include sensitive venue data in the first message.

Return home