High / critical findings
Codex Security found one low CSP item in the prior snapshot. It was remediated and independently rescanned.
SCAN ID · B9435071PUBLIC CONTROL EVIDENCE · 28 AUG 2026
This page records what was tested, who performed the check and where the boundary ends. It is a technical baseline—not an ISO 27001 or SOC 2 certification.
CURRENT EVIDENCE
Grades and review statements are dated snapshots. They do not guarantee that a system can never be compromised.
10 of 10 tests passed after strict-CSP remediation. Score 130 / 100 on 28 August 2026.
VIEW PUBLIC RESULT ↗Codex Security found one low CSP item in the prior snapshot. It was remediated and independently rescanned.
SCAN ID · B9435071Checked against the npm advisory database for the locked production dependency graph.
NPM AUDIT · 28 AUG 2026CONTROL REGISTER
HONEST SCOPE
The current app is a read-only product preview. It has no customer login, private portfolio data, exchange credentials, custody or order execution. Those capabilities require a new review of identity, tenant isolation, secrets management, audit logging and incident response before release.
Report the affected URL, steps to reproduce and potential impact. Do not access data that is not yours, disrupt service or attempt social engineering.
Report a security issue