Disclosure, posture, and contact.
Umbra runs the same kind of probes you'd point at your own infrastructure. We treat reports about our own surface the way we'd want our customers' findings handled, promptly, calmly, and with credit where it's due.
90-day window standard.
Report any vulnerability via the security inbox below. We acknowledge within one business day, ship a fix or mitigation as fast as the issue warrants, and publish a writeup with credit (opt-out available) once any affected customer has had time to update. We follow a 90-day disclosure window unless the issue is actively exploited.
One inbox, monitored daily.
Send reports to
security@umbrascope.com
. PGP key fingerprint and full public key are published at
/.well-known/security.txt.
Include reproduction steps, affected component, and any
proof-of-concept you ran. We'll mirror our own report format
back to you when we triage.
EU residency, no resale, no training.
Customer data lives in EU (Hetzner Falkenstein) by default; US region available on request. We do not sell customer data, do not share it with third parties beyond named subprocessors (Paddle for billing, Postmark for transactional email, DeepSeek and Anthropic for AI runs you trigger), and do not train models on it. A signed DPA is available on request to hello@umbrascope.com .
What your auditor sees when you sign up.
The features below are what your SOC 2 / ISO 27001 / NIS2 / GDPR Art. 32 auditor actually reads, not promises, not roadmap items. Click any link for the docs.
- Compliance evidence pack: maps Umbra's data to specific SOC 2 / ISO 27001 / NIS2 / GDPR Article 32 control IDs, generated on demand for any audit window. Browser Print → Save as PDF, plus Markdown export.
- Shareable compliance pack: mint a password-gated public URL to a redacted snapshot of the evidence pack. Send to your customer's security team instead of writing a questionnaire response by hand.
- Cloud security posture: reads the AWS / Google Cloud / Azure control plane to find world-readable data, privesc-to-admin, and internet-open services a port scan can't see. Read-only, least-privilege role, never writes to your cloud.
- Audit log viewer: every privileged action in the workspace (target add / delete, role change, agent enrolment, billing change) with actor, timestamp, and JSON detail. CSV export for forensic review.
- Roles + per-target ACL: four-tier role model (org_viewer / org_member / org_admin / org_owner) plus per-target grants for the cases where a teammate should only see one customer's scope.
- Module-level access control: grant a teammate only the modules they need (e.g. Deep Audit only) for least-privilege / separation-of-duties. Enforced server-side, not just hidden in the UI.
- Single sign-on: OIDC with Google and Microsoft, so access follows your identity provider's joiner/mover/leaver process (Pro and up).
- Findings lifecycle: every finding moves through a documented state machine (open → in_progress → fixed → verified, or wontfix for accepted risk) with MTTR computed automatically.
What's in flight.
- SOC 2 Type II certification: engagement opens once the first paying Business-tier customer requires it. The in-product evidence pack ships today regardless.
- ISO 27001 certification: same trigger as above.
- Live status page: uptime and incident log at status.umbrascope.com .