HOKUSECURITY CENTERBack to product

PUBLIC CONTROL EVIDENCE · 28 AUG 2026

HOKU SECURITYBASELINE VERIFIEDScope: app.hoku.ventures

Verified controls.
No vague promises.

This page records what was tested, who performed the check and where the boundary ends. It is a technical baseline—not an ISO 27001 or SOC 2 certification.

CURRENT EVIDENCE

Every badge must resolve to evidence.

Grades and review statements are dated snapshots. They do not guarantee that a system can never be compromised.

INDEPENDENT HTTP SCANA+

Mozilla Observatory

10 of 10 tests passed after strict-CSP remediation. Score 130 / 100 on 28 August 2026.

VIEW PUBLIC RESULT ↗
AUTOMATED CODE REVIEW0

High / critical findings

Codex Security found one low CSP item in the prior snapshot. It was remediated and independently rescanned.

SCAN ID · B9435071
SUPPLY CHAIN CHECK0

Known production advisories

Checked against the npm advisory database for the locked production dependency graph.

NPM AUDIT · 28 AUG 2026

CONTROL REGISTER

What is protected today.

TransportHTTPS redirect + HSTSVERIFIED
Browser isolationNonce CSP + frame denialVERIFIED
Application boundaryNo accounts, custody or trading keysVERIFIED
Dependencies0 known production vulnerabilitiesVERIFIED
DisclosureRFC 9116 security.txtPUBLISHED
Edge telemetryExploit-path rule staged log-onlyREVIEW

HONEST SCOPE

Strong public baseline.
Not enterprise certification—yet.

The current app is a read-only product preview. It has no customer login, private portfolio data, exchange credentials, custody or order execution. Those capabilities require a new review of identity, tenant isolation, secrets management, audit logging and incident response before release.

OWASP ASVS 5.0FRAMEWORK REFERENCEDNot an OWASP certification
RFC 9116IMPLEMENTEDPublic security.txt
Vercel DDoS mitigationPLATFORM CONTROLInfrastructure protection
SOC 2 / ISO 27001NOT CERTIFIEDRequires independent organizational audit
RESPONSIBLE DISCLOSURE

Found something?

Report the affected URL, steps to reproduce and potential impact. Do not access data that is not yours, disrupt service or attempt social engineering.

Report a security issue