Security

Protect the surface. Define the test.

Mediator separates the security posture of its own public surfaces from security validation performed for an authorized customer. A public request is not permission to probe a system.

Public Surface

Edge protection

Public website traffic is routed through the deployed edge. Availability and front-surface controls are kept separate from product-runtime claims.

Authorized Validation

Reaper testing boundary

Scoped validation can cover web, API, configuration, tenant isolation, AI-agent tools and approval gates, repositories/configuration, and infrastructure exposure after written authority and Rules of Engagement are recorded.

Evidence

Findings that can be retested

Findings are captured with reproduction conditions, impact context, remediation guidance, evidence, and a retest decision. Blackbox Systems may preserve the evidence produced by an authorized engagement; it does not grant testing authority.

Continuous Oversight

Monitored, observable, time-stamped

Public surfaces run on continuously monitored infrastructure with logging, metrics and alerting, so anomalies are seen and time-stamped as they happen rather than reconstructed afterward.

Governed Identity

Enterprise identity for people and agents

Access to operator and product surfaces runs on enterprise identity — single sign-on, multi-factor and role-based authority. Mediator is pursuing Okta as its identity partner for the layer that agent operations increasingly depend on.

Agent Identity

Identity your agents can prove

Mediator’s agents carry persistent, governed identity — durable personas with their own authority boundaries, receipts and lifecycle. It is built to slot into the identity stack a team already runs, adding accountable agent identity to what they have.

Default Deny

Nothing outside the written boundary is implied.

Domains, IP ranges, APIs, cloud resources, repositories, identities, testing windows, allowed methods, impact limits, and escalation contacts are defined before active probing. Connected third-party infrastructure is excluded unless separately authorized.

Cold intrusion, credential theft, credential stuffing, covert persistence, and out-of-scope extraction are not public product behavior. If authority or scope becomes ambiguous, testing stops until clarified in writing.

Disclosure

Found something on a Mediator-owned surface?

Good-faith reports relating to Mediator-owned public assets can be sent to security@mediatorsolutions.io. The public security file is available at /.well-known/security.txt.