Trust center
Secure development
How the product is built, reviewed and released.
Development follows practices aligned with IEC 62443-4-1, the secure product development lifecycle standard for industrial automation. The written SDLC policy and threat model are in the security pack.
| Practice | Status |
|---|---|
| Every change merged through a pull request with automated checks | In place |
| Type checking, unit tests and container build on every change | In place |
| Container smoke test and security header check in CI | In place |
| SBOM, vulnerability gate and signing on every release | In place |
| Hostile-input test cases for the XML and CSV parsers | In place |
| Written threat model (in the security pack) | In place |
| Written SDLC and dependency policy (in the security pack) | In place |
| Formal IEC 62443-4-1 certification | Not planned yet |
Scope rule: features that need a live write to a production system are out of scope.
Last updated 2026-10-04.