Fluxdyne

Home / Security

Security.

Security is the product at Fluxdyne: our systems exist to preserve evidence integrity. This page describes our posture in plain terms. It lists practices, not certifications.

Product security

DynamicFeed responses are signed with Ed25519 keys whose public halves are published, versioned and lifecycle-managed at dynamicfeed.ai/.well-known/keys. Open-source verifiers are published on PyPI, npm and crates.io so anyone can verify responses independently of us. Receipts are tamper-evident, not tamper-proof: signatures establish integrity and attribution, not objective truth.

Platform practices

All traffic is served over TLS. Production access is restricted and credentialed; secrets are stored in the deployment platform's managed configuration, never in source control. The corporate site collects nothing beyond the enquiry form described in the privacy notice.

Reporting a vulnerability

We welcome good-faith security reports. Describe the issue through the contact form and we will respond by email. Please avoid accessing data that is not yours and give us reasonable time to remediate before public disclosure.