Tank's security model is single-tenant and private — no public SaaS tenant, no shortcuts.
Every row below carries its evidence tier. “Measured” is a counter or query from the running system. “Api-declared” is read live from the deployed API's own declaration — drift-proof against this page, but self-reported. “Regression-tested” is enforced in code and asserted by a named repository test, but not observable from this browser. “Policy” is documentation: no machine check runs for it.
Opens print-optimized HTML — use Ctrl+P / ⌘P to save as PDF
Checking live security evidence
The live, API-declared version of this claim is in Compliance posture above.
Host configuration — not observable from this page.
Tank is invite-only. Accounts are created only with a valid invite code.
Asserted by test_register_with_invalid_invite_code. Not probed from this page — probing it would mean attempting a registration.
The scheme is asserted by test_local_auth_uses_pbkdf2. The iteration count and 12-character minimum are in code but not yet pinned by a test.
Tank exposes one read-only MCP tool, get_latest_spikes, at POST /v1/mcp/patent-watch. Every call needs a signed-in bearer token and counts against the shared run rate limit.
Asserted by test_verify_tool_witness_raises_on_mismatch.
Bootstrap behaviour asserted by test_check_principal_allowed_bootstrap_mode.
Enforced by tests/test_no_raw_subprocess.py.
In code; no test asserts it yet.
Writes only when the audit path is configured; whether it is enabled on this deploy is not visible here.
If you discover a security issue, please contact us directly.
security@tempproject.online