Documentation / Security & Compliance
Businesses connecting their information and systems to the TechDex AI Framework need to understand what has been checked, what remains under review, and which responsibilities belong to their own organization. This page records that work as it progresses.
Security checklist at a glance
Checked boxes mean Passed. Open boxes mean Needs work or Not tested. Results cover the TechDex test installation and reviewed code.
| Check | Protection | Status | What this means |
|---|---|---|---|
| Checked | Sign-in required | Passed | visitors without an authorized login cannot use the tested employee chat or retrieve its history. |
| Checked | Login request protection | Passed | a login request missing its security token was rejected, and a supplied, unrecognized session identifier was replaced. |
| Checked | Employee database histories | Passed | Employee database history and recall are restricted to the signed-in account. Existing ownership tests passed; public and employee records use separate database stores. |
| Checked | Restricted file access | Passed | tested private configuration, diagnostic, backup and resource locations reject public access. |
| Checked | API access checks | Passed | missing or invalid credentials were rejected; the authorized read-only capability check worked. |
| Checked | Safe display of messages | Passed | Representative text and markup checks passed in both chat interfaces. User text is escaped for display. |
| Checked | Error privacy | Passed | Browser error display is disabled, and diagnostic logs are protected from public access. Configuration and response handling were reviewed. |
| Unchecked | Encrypted connections | Needs work | HTTPS works, but the hosting connection settings need further tightening. |
| Unchecked | File uploads | Not tested | Uploads are unavailable on this installation. The required database update and upload-access tests are scheduled for the next release. |
| Checked | Safe updates and recovery | Passed | Update integrity checks passed. The current updater restored original files and version information after a simulated failure, and rejected unsafe or incomplete packages. |
| Unchecked | Ongoing protection | Not tested | Company-selected retention periods, ongoing monitoring reviews and vulnerability-management records need operational evidence. These are separate from the completed product checks. |
| Unchecked | Company procedures | Not tested | staff access reviews, policies, training and supplier responsibilities require organizational evidence. |
| Unchecked | Temporary conversation access | Needs work | The review found an additional access boundary to strengthen in temporary conversation handling. The separate database design remains established; this item stays open until repaired and tested. |
Details explain what was checked and what remains to be done.
What is being assessed
The current authorized live test scope is ai.techdex.net only, covering the public-facing interface and authenticated administration workspace. Client installations are outside this live test scope. Tests are bounded and non-destructive.
The broader readiness review also considers TechDex's development and release processes, central API, licensing and update services, connected data sources, and responsibilities shared with hosting and service providers. The boundary of any future independent assessment still needs to be formally defined.
Completed checks
On September 28, 2026, the initial five local test suites passed:
- Role-permission rules.
- Installation-secret persistence.
- License-signature authentication rules.
- Session boundaries between installations.
- Privacy masking in dashboard output.
These include checks of source-code rules and limited behavioral tests. They establish that those tests passed against the local code reviewed; they do not establish that every deployed control works correctly or that the system is free of vulnerabilities.
A subsequent bounded assessment passed 11 selected local suites in total, including those five. Live checks on ai.techdex.net confirmed HTTPS redirection, rejection of an unauthenticated administration-chat request, and protected admin-cookie attributes. Representative text and markup samples remained inert in both chat interfaces. The public chat retained the tested history safely after reload.
Further work is required. The assessment identified access-protection, file-handling, and error-handling items for remediation and retesting. An initial backend availability failure interrupted the first reload check; a subsequent check recovered the saved conversation successfully. Sensitive finding details are retained privately. These results do not support a claim of completed compliance.
Hardening and retesting
Version 1.1.49 is published with matching update and installer packages. Protections were deployed on ai.techdex.net and checked: direct diagnostic and configuration requests were rejected, restricted upload paths were denied, and both public and authenticated workspace conversations completed normally. The development console uses separate password authentication and is excluded from client packages. All 84 selected PHP regression suites passed.
Browser error display is disabled in deployed configuration and runtime entry points. The current updater also passed an isolated failed-update recovery exercise. No production outage or uploaded executable was used. Independent assessment remains separate.
Assessment work still pending
- Conversation access: complete the temporary-history access repair while preserving stored conversations.
- Connection protection: tighten the hosting connection settings and release the tested credential-integrity repair.
- File uploads: deliver the scheduled database migration and verify upload and download permissions before enabling the module.
- Organizational and operational evidence: policies, risk decisions, staff and supplier processes, monitoring reviews, retention schedules and hosting backup arrangements require evidence from their responsible owners.
Completed technical checks are supported by documented implementation, existing tests and targeted verification. Testing every possible failure is not a completion requirement. Additional browser-policy hardening is tracked separately.
How results will be reported
Each assessment update will distinguish code reviewed, local tests passed, live behavior checked, operational evidence reviewed, and items still awaiting evidence. Findings will retain their assessment date and scope. Repairs will be distinguished from successful retests.
This public page will contain a summary suitable for customers and reviewers. Credentials, private records, sensitive diagnostic details, and information that could expose an unresolved vulnerability will remain outside the public record.
Shared responsibilities
TechDex is the company responsible for the services and development processes it operates. The TechDex AI Framework is the product being reviewed. Customer-hosted installations also depend on the customer's hosting security, database permissions, account administration, configuration, and backup arrangements. External providers have responsibilities for their own services.
An assessment of TechDex's defined service boundary would not, by itself, certify a customer's entire infrastructure. These responsibilities must be documented before making broader assurance claims.
ISO/IEC 27001 and SOC 2
ISO/IEC 27001 concerns an organization's information security management system within a defined scope, including people, processes, and technology. SOC 2 involves an independent examination and report on controls over a defined service system. Application tests contribute evidence to readiness work; they do not replace either independent process.
The appropriate assurance route will be selected according to customer requirements and the service scope. Any future certification or examination status will be reported with its actual scope and supporting details.