Security
Sovereignty demands custody. Here is how THE SOVEREIGN UMBRELLA COMMAND protects your empire.
SOC 2-Compliant Infrastructure
The Command OS runs on cloud infrastructure operated under SOC 2 Type II attested controls — continuous monitoring, least-privilege access, audited change management, and encrypted transport (TLS 1.2+) on every connection.
ISO 20022-Compliant Financial Processing
Financial flows are processed through Stripe's payment rails, which interoperate with the ISO 20022 financial messaging standard adopted by modern banking networks — structured, auditable, machine-readable transaction data end to end.
Encryption Everywhere
Vault documents are sealed with Fernet symmetric encryption (AES-128-CBC + HMAC). Passwords are bcrypt-hashed. Gmail app passwords are encrypted at rest. Sessions ride httpOnly secure cookies — never browser storage.
Execution Guardrails
Code runs in isolated sandboxes with CPU/memory caps. Browser automation is read-only and SSRF-guarded against private networks. Every executed action archives an encrypted, signed record — a permanent audit trail.
Additional Controls
- Strict multi-tenant isolation — every query is scoped to your account ID at the database layer.
- Financial double-gate: no charge fires without a stored payment method AND your explicit per-transaction approval.
- Dead Man's Switch: configurable inactivity failsafe that alerts your designated beneficiary.
- Live Stripe keys are verified against Stripe before activation and stored in secured configuration — never in client code.
- Vault key rotation is supported and logged.
Disclosure
Found a vulnerability? Report it to security@umbrellacommand.example. We acknowledge within 48 hours and do not pursue good-faith researchers.