Trust

Security & Trust

How Sixfold OS protects your data: delegated authentication, least-privilege access, per-module isolation, audit and governance records, encryption, and sub-processors.

Last updated: 4 July 2026

This document is a template provided for information only. It is not legal advice and not a certification. Any remaining placeholders in square brackets must be completed, and the whole text reviewed by qualified counsel, before it is relied upon.

1. Security posture

Security is built into the architecture of Sixfold OS rather than added afterwards. Our controls are designed to align with the ISO/IEC 27001 information-security framework. Alignment with a framework is a design objective and is stated here for information; it is not itself a certification.

2. Delegated authentication

Identity is authenticated externally by Auth0 (Okta, Inc.) and single sign-on, and mirrored into Sixfold OS as minimal identity claims. Sixfold OS does not store user passwords. The authentication tenant is configured in the European region.

3. Least-privilege access control

Access is governed by role-based access control with least-privilege defaults. Effective permissions are derived from the intersection of assigned roles and scopes, so access is granted only where a role explicitly allows it (default-deny).

  • Roles are scoped at the system, tenant, or workspace level.
  • Module-specific scopes gate read, review, and administer actions.
  • Governance roles (for example governance steward and auditor) provide dedicated review and evidence access.

4. Per-tenant and per-module isolation

Data is isolated by tenant, by workspace, and by module namespace. Every governed resource carries a tenant and workspace envelope, and access is enforced against a resource boundary — a request whose access context does not match the tenant/workspace scope is rejected. Module data stays isolated within its namespace and is not shared across modules by default.

5. Audit and governance records

Governance actions produce durable records used for accountability and assessment, including policy acknowledgements, review approvals, and integrity-gate outcomes. Governance workflows enforce integrity gates (for example manipulation, cognitive-load, inclusivity, and telemetry-transparency checks) and steward approval before designated actions can proceed.

  • Audit evidence supports what an assessor typically expects to see for a given standard.
  • Review cycles and steward assignments provide traceable accountability.
  • Security-relevant events are logged with timestamps and actor context.

6. Encryption

Traffic to the service is encrypted in transit using TLS. Session cookies are protected with a dedicated encryption key. Data at rest is protected by the encryption capabilities of our hosting and database providers. [Confirm specific at-rest encryption details with your infrastructure provider.]

7. Sub-processors

We use a limited set of sub-processors to operate the service:

Auth0 (Okta, Inc.)

Authentication, session issuance, and single sign-on.

[Hosting / infrastructure provider]

Application and database hosting.

[Email / communications provider]

Transactional email and support communications.

[Additional sub-processors]

Any further processors are listed here and updated as the service evolves.

Each sub-processor is engaged under a data processing agreement. To request the current sub-processor list or report a security concern, contact admin@sixfoldux.com.

8. Reporting a vulnerability

If you believe you have found a security vulnerability, please report it responsibly to admin@sixfoldux.com and allow us reasonable time to investigate and remediate before public disclosure.