Public Surface
Edge protection
Public website traffic is routed through the deployed edge. Availability and front-surface controls are kept separate from product-runtime claims.
Security
Mediator separates the security posture of its own public surfaces from security validation performed for an authorized customer. A public request is not permission to probe a system.
Public Surface
Public website traffic is routed through the deployed edge. Availability and front-surface controls are kept separate from product-runtime claims.
Authorized Validation
Scoped validation can cover web, API, configuration, tenant isolation, AI-agent tools and approval gates, repositories/configuration, and infrastructure exposure after written authority and Rules of Engagement are recorded.
Evidence
Findings are captured with reproduction conditions, impact context, remediation guidance, evidence, and a retest decision. Blackbox Systems may preserve the evidence produced by an authorized engagement; it does not grant testing authority.
Continuous Oversight
Public surfaces run on continuously monitored infrastructure with logging, metrics and alerting, so anomalies are seen and time-stamped as they happen rather than reconstructed afterward.
Governed Identity
Access to operator and product surfaces runs on enterprise identity — single sign-on, multi-factor and role-based authority. Mediator is pursuing Okta as its identity partner for the layer that agent operations increasingly depend on.
Agent Identity
Mediator’s agents carry persistent, governed identity — durable personas with their own authority boundaries, receipts and lifecycle. It is built to slot into the identity stack a team already runs, adding accountable agent identity to what they have.
Default Deny
Domains, IP ranges, APIs, cloud resources, repositories, identities, testing windows, allowed methods, impact limits, and escalation contacts are defined before active probing. Connected third-party infrastructure is excluded unless separately authorized.
Cold intrusion, credential theft, credential stuffing, covert persistence, and out-of-scope extraction are not public product behavior. If authority or scope becomes ambiguous, testing stops until clarified in writing.
Disclosure
Good-faith reports relating to Mediator-owned public assets can be sent to security@mediatorsolutions.io. The public security file is available at /.well-known/security.txt.