SECURITY STATEMENT

Security

Sovereignty demands custody. Here is how THE SOVEREIGN UMBRELLA COMMAND protects your empire.

SOC 2-Compliant Infrastructure

The Command OS runs on cloud infrastructure operated under SOC 2 Type II attested controls — continuous monitoring, least-privilege access, audited change management, and encrypted transport (TLS 1.2+) on every connection.

ISO 20022-Compliant Financial Processing

Financial flows are processed through Stripe's payment rails, which interoperate with the ISO 20022 financial messaging standard adopted by modern banking networks — structured, auditable, machine-readable transaction data end to end.

Encryption Everywhere

Vault documents are sealed with Fernet symmetric encryption (AES-128-CBC + HMAC). Passwords are bcrypt-hashed. Gmail app passwords are encrypted at rest. Sessions ride httpOnly secure cookies — never browser storage.

Execution Guardrails

Code runs in isolated sandboxes with CPU/memory caps. Browser automation is read-only and SSRF-guarded against private networks. Every executed action archives an encrypted, signed record — a permanent audit trail.

Additional Controls

  • Strict multi-tenant isolation — every query is scoped to your account ID at the database layer.
  • Financial double-gate: no charge fires without a stored payment method AND your explicit per-transaction approval.
  • Dead Man's Switch: configurable inactivity failsafe that alerts your designated beneficiary.
  • Live Stripe keys are verified against Stripe before activation and stored in secured configuration — never in client code.
  • Vault key rotation is supported and logged.

Disclosure

Found a vulnerability? Report it to security@umbrellacommand.example. We acknowledge within 48 hours and do not pursue good-faith researchers.

THE SOVEREIGN UMBRELLA COMMAND uses one strictly-necessary session cookie for secure authentication — no advertising or cross-site tracking. Details in our Privacy Policy.