Security
Security model
WarnFire is designed for tenant-isolated incident response. Public documentation never contains live credentials, integration keys, push tokens, tenant payloads, or internal operational logs.
Credential handling
- Store integration keys in a secret manager.
- Rotate a key immediately if it appears in a URL, screenshot, chat, issue, or log.
- Use responder-scoped mobile access and revoke lost devices.
- Use the narrowest administrative role needed for a task.
Event content
Incident payloads can contain operationally sensitive values. Send only information responders need, and use links to protected source systems for large or highly sensitive records.
Reporting
Report suspected vulnerabilities to security@warnfire.com. Do not include active credentials or access data belonging to another customer.