The summary below is the public-facing description of how Innovexus is built. The detailed security whitepaper, the most recent third-party penetration-test report, and any SOC 2-style evidence package are available on request under mutual NDA via the trust mailbox.
Innovexus is a single self-contained appliance you run on your own infrastructure — compute, storage, and network are entirely yours, not shared with anyone. The appliance hosts the credential vault, session broker, audit chain, and identity surface for your organisation, and it does not call home to any control plane.
FIDO2/WebAuthn hardware authentication (YubiKey-class devices) at the platform login. SAML 2.0 and OIDC SSO with any standards-compliant IdP (Okta, Azure AD, JumpCloud, Google Workspace). SCIM 2.0 provisioning. Local-username authentication available as a fallback against organisation-managed databases or AD/LDAP.
AES-256-GCM encryption at rest for all vaulted credentials. The appliance mints its own encryption key on first boot; it never leaves the appliance and is not shared across deployments, so one extracted image cannot decrypt another organisation's vault. Credential rotation is automated (default 24-hour cycle) and atomic with respect to the AAA decision point.
Engineer endpoints connect to the appliance; the appliance brokers the SSH, Telnet, console, RDP, or web-admin session to the target. It is the only authorised source for management connections to enrolled devices (IP allowlisting). Engineers never possess the device-side credential.
Every audit event is hash-chained and signed by the appliance's signing key. Tampering with a session record breaks the signature chain and is detectable on audit. Audit retention default: 90 days for full session video, 7 years for signed audit metadata. Both retention windows are configurable.
TLS 1.3 with mutual authentication where supported. SSH protocol versions hardened to current OpenSSH defaults; legacy ciphers disabled. The certificate authority for ephemeral SSH cert issuance is local to your appliance; there is no cross-organisation CA trust.
The boundary diagram below is a public summary of the trust boundaries the detailed threat model treats in depth. Each boundary is the subject of a specific control set in the full whitepaper.
The Innovexus application undergoes third-party security review covering the application surface, authentication and session brokering layers, and audit-chain integrity. Because the software is open source, the code is also open to inspection by anyone. Fixes land in the published appliance images on the downloads page.
We accept responsible vulnerability reports via [email protected]. PGP key available on request. Standard 90-day coordinated disclosure window. We do not pursue legal action against good-faith security researchers following the disclosure policy.
Full architecture document covering control families, key custody specifics, threat model walkthrough, and incident response procedures. ~30-page PDF, shared under mutual NDA.
Most recent annual pen-test report from our independent testing firm. Includes scope, methodology, findings, and remediation status. Shared under NDA after a brief security review of the requestor.
Innovexus does not independently hold a SOC 2 Type II attestation (see /compliance), but the appliance produces an evidence package mapped to SOC 2 Trust Services Criteria for your own audit purposes — control descriptions and sample evidence you can export directly from the box.
Because you self-host, there is no data-processing agreement to sign with Innovexus — the software never receives your operational data. Your data handling is governed by your own environment and policies.
Backup and recovery are yours to run against your own infrastructure. The appliance supports configuration and database backup so you can meet whatever RPO/RTO your environment requires.
Email the trust mailbox with a brief description of your use case (a sentence or two — vendor evaluation, security review, etc.). We'll send an NDA template and the requested artifacts within one business day.