WWarnFireDocs

Security

Security model

WarnFire is designed for tenant-isolated incident response. Public documentation never contains live credentials, integration keys, push tokens, tenant payloads, or internal operational logs.

Credential handling

  • Store integration keys in a secret manager.
  • Rotate a key immediately if it appears in a URL, screenshot, chat, issue, or log.
  • Use responder-scoped mobile access and revoke lost devices.
  • Use the narrowest administrative role needed for a task.

Event content

Incident payloads can contain operationally sensitive values. Send only information responders need, and use links to protected source systems for large or highly sensitive records.

Reporting

Report suspected vulnerabilities to security@warnfire.com. Do not include active credentials or access data belonging to another customer.