Security Policy
1. Architecture
NSIGNIS OSIDECK runs client-side: the Dashboard is based on technologies executed in your browser, which fetches data directly from public third-party services. NSIGNIS LTD operates no account system and no server-side processing of personal data for the public Dashboard. Serve and access the Dashboard over HTTPS; browsers additionally require HTTPS for the optional GPS-location fallback.
2. NSIGNIS LTD data layers and access codes
The NSIGNIS LTD Intelligence and NSIGNIS LTD Sensory layers are restricted capabilities, activated only for parties preauthorized in writing by NSIGNIS LTD:
- Access codes are confidential credentials. Treat them like passwords: do not share, embed in screenshots, or store them in plaintext.
- The Dashboard holds an entered code in page memory for the session only; it is masked on entry and is not persisted to disk by the Dashboard.
- In addition to Access Codes, we may also use Biometric identification technologies.
- If you suspect your access has been exposed or misused, notify NSIGNIS LTD immediately at [email protected]; access can be revoked and reissued.
- Attempting to access NSIGNIS LTD layers without preauthorization, including code guessing, replay or endpoint probing, is prohibited (see Terms of Use §4) and may be a criminal offense under applicable computer-misuse legislation.
3. Third-party dependencies
The Dashboard loads the Leaflet library from the cdnjs content-delivery network and calls the public APIs listed in the Privacy Policy. Operators self-hosting NSIGNIS OSIDECK should pin dependency versions, apply subresource-integrity attributes where practicable, and restrict any API keys they configure (for example Google Places or TomTom) by referrer and API scope so that a leaked key cannot be abused.
4. Data integrity (read the labels)
Security decisions demand knowing the pedigree of each datum. The Dashboard labels every card's source: live means third-party feed; model / indicative / curated means an NSIGNIS LTD heuristic estimate; cached / sample means fallback content shown when feeds are unreachable. The alerting system deduplicates and gates by severity for readability, it is not a life-safety warning channel and must never be your only alarm path for evacuations, air raids, severe weather or similar events. Always maintain access to official warning systems.
5. Reporting a vulnerability
NSIGNIS LTD welcomes good-faith security research on NSIGNIS LTD owned assets:
- Report suspected vulnerabilities to [email protected] with reproduction steps; we will acknowledge receipt and keep you informed of remediation.
- Do not access, modify or exfiltrate data belonging to others; do not degrade service; do not run automated scanning against the third-party data providers, they are not NSIGNIS LTD assets and testing them is outside any authorization NSIGNIS LTD can grant.
- Public disclosure should be coordinated: give NSIGNIS LTD reasonable time to remediate before publishing.
- Good-faith research conducted within these rules will not be met with legal action by NSIGNIS LTD. No bug bounty is implied unless separately agreed.
6. Operator hardening checklist
- Serve over HTTPS with HSTS; keep TLS configuration current.
- Set a Content-Security-Policy limiting script/style/frame sources to the documented providers.
- Add referrer and scope restrictions to any configured API keys; never commit keys to public repos.
- Review the provider list after updates, new cards can introduce new endpoints.
- Keep browsers and the hosting stack patched; the Dashboard has no server logic to patch, but the platform serving it does.
7. Incidents
Suspected compromise involving NSIGNIS LTD layers, access codes or NSIGNIS LTD-operated infrastructure: [email protected], subject line "SECURITY INCIDENT".
This policy describes the Dashboard as built and NSIGNIS LTD's disclosure preferences. It does not grant authorization to test third-party services and does not replace the Terms of Use.
NSIGNIS