Legal
Security Practices
Last updated: 2026-05-06
Authwright is designed around workspace isolation, broker-owned credential handling, and auditability for operational actions.
Credential boundary
Registrar credential material is not handled by portal application code. Credential ingestion and use are broker-owned.
Access control
Portal sessions are opaque, revocable, and scoped to a user plus active workspace. MCP tokens are planned as workspace-scoped and revocable.
Compliance
Authwright runs on Microsoft Azure, inheriting its SOC 2, ISO 27001, and regional compliance posture. A SOC 2 Type II report for Authwright itself is on the roadmap; current measures are described above.
Reporting a vulnerability
We welcome responsible disclosure. Send security reports to security@authwright.com — we acknowledge within 2 business days.
Contact
Questions? security@authwright.com