Architecture and boundaries
The public web application communicates with a gateway layer; the canonical application service is not intended to be exposed directly to browsers. Application records are scoped to a workspace, and protected routes require an authenticated session. The exact production topology and infrastructure providers are deployment-specific.
Authentication and authority
- Account sessions and protected application routes.
- Multi-factor enrolment and recovery surfaces.
- Workspace roles and explicit approval stages.
- Human gates for decisions reserved by policy, role or configured threshold.
Identity-provider, provisioning and enterprise access requirements are validated during discovery; they are not implied by a public plan card.
Data and transport
Production web traffic is served over HTTPS. The product keeps request context, evidence and provider responses attached to workspace records. Storage encryption, backup, region, recovery objectives and subprocessor details depend on the selected production deployment and are documented before contracting.
Audit and automation
Severus records approval, activity and provider-response events for review inside the product. Snape is designed to operate through configured permissions and approval gates. An audit record does not make an external action—such as a completed bank transfer—reversible; the provider outcome remains part of the evidence.
Assurance and incident terms
We do not claim a certification, fixed hosting region, universal retention period or response-time commitment on this public page. Required assurance material, incident contacts, notification terms, recovery objectives and service levels should be recorded in the applicable order form, security schedule or data-processing agreement.
Reporting issues
Send vulnerability disclosures privately to security@severus.ng. Please do not include live credentials, payment-card details or unnecessary customer data. Disclosure instructions are also published at /.well-known/security.txt.