TechDex AI Framework ™

Security & Compliance Readiness

Documentation / Security & Compliance

Businesses connecting their information and systems to the TechDex AI Framework need to understand what has been checked, what remains under review, and which responsibilities belong to their own organization. This page records that work as it progresses.

Current status: readiness assessment in progress. Updated . This page does not claim ISO/IEC 27001 certification or a completed SOC 2 examination. The checks below are preliminary evidence, not a completed compliance determination.

Security checklist at a glance

Checked boxes mean Passed. Open boxes mean Needs work or Not tested. Results cover the TechDex test installation and reviewed code.

Assessment progress · September 28, 2026
CheckProtectionStatusWhat this means
CheckedSign-in requiredPassedvisitors without an authorized login cannot use the tested employee chat or retrieve its history.
CheckedLogin request protectionPasseda login request missing its security token was rejected, and a supplied, unrecognized session identifier was replaced.
CheckedEmployee database historiesPassedEmployee database history and recall are restricted to the signed-in account. Existing ownership tests passed; public and employee records use separate database stores.
CheckedRestricted file accessPassedtested private configuration, diagnostic, backup and resource locations reject public access.
CheckedAPI access checksPassedmissing or invalid credentials were rejected; the authorized read-only capability check worked.
CheckedSafe display of messagesPassedRepresentative text and markup checks passed in both chat interfaces. User text is escaped for display.
CheckedError privacyPassedBrowser error display is disabled, and diagnostic logs are protected from public access. Configuration and response handling were reviewed.
UncheckedEncrypted connectionsNeeds workHTTPS works, but the hosting connection settings need further tightening.
UncheckedFile uploadsNot testedUploads are unavailable on this installation. The required database update and upload-access tests are scheduled for the next release.
CheckedSafe updates and recoveryPassedUpdate integrity checks passed. The current updater restored original files and version information after a simulated failure, and rejected unsafe or incomplete packages.
UncheckedOngoing protectionNot testedCompany-selected retention periods, ongoing monitoring reviews and vulnerability-management records need operational evidence. These are separate from the completed product checks.
UncheckedCompany proceduresNot testedstaff access reviews, policies, training and supplier responsibilities require organizational evidence.
UncheckedTemporary conversation accessNeeds workThe review found an additional access boundary to strengthen in temporary conversation handling. The separate database design remains established; this item stays open until repaired and tested.

Details explain what was checked and what remains to be done.

What is being assessed

The current authorized live test scope is ai.techdex.net only, covering the public-facing interface and authenticated administration workspace. Client installations are outside this live test scope. Tests are bounded and non-destructive.

The broader readiness review also considers TechDex's development and release processes, central API, licensing and update services, connected data sources, and responsibilities shared with hosting and service providers. The boundary of any future independent assessment still needs to be formally defined.

Completed checks

On September 28, 2026, the initial five local test suites passed:

These include checks of source-code rules and limited behavioral tests. They establish that those tests passed against the local code reviewed; they do not establish that every deployed control works correctly or that the system is free of vulnerabilities.

A subsequent bounded assessment passed 11 selected local suites in total, including those five. Live checks on ai.techdex.net confirmed HTTPS redirection, rejection of an unauthenticated administration-chat request, and protected admin-cookie attributes. Representative text and markup samples remained inert in both chat interfaces. The public chat retained the tested history safely after reload.

Further work is required. The assessment identified access-protection, file-handling, and error-handling items for remediation and retesting. An initial backend availability failure interrupted the first reload check; a subsequent check recovered the saved conversation successfully. Sensitive finding details are retained privately. These results do not support a claim of completed compliance.

Hardening and retesting

Version 1.1.49 is published with matching update and installer packages. Protections were deployed on ai.techdex.net and checked: direct diagnostic and configuration requests were rejected, restricted upload paths were denied, and both public and authenticated workspace conversations completed normally. The development console uses separate password authentication and is excluded from client packages. All 84 selected PHP regression suites passed.

Browser error display is disabled in deployed configuration and runtime entry points. The current updater also passed an isolated failed-update recovery exercise. No production outage or uploaded executable was used. Independent assessment remains separate.

Assessment work still pending

Completed technical checks are supported by documented implementation, existing tests and targeted verification. Testing every possible failure is not a completion requirement. Additional browser-policy hardening is tracked separately.

How results will be reported

Each assessment update will distinguish code reviewed, local tests passed, live behavior checked, operational evidence reviewed, and items still awaiting evidence. Findings will retain their assessment date and scope. Repairs will be distinguished from successful retests.

This public page will contain a summary suitable for customers and reviewers. Credentials, private records, sensitive diagnostic details, and information that could expose an unresolved vulnerability will remain outside the public record.

Shared responsibilities

TechDex is the company responsible for the services and development processes it operates. The TechDex AI Framework is the product being reviewed. Customer-hosted installations also depend on the customer's hosting security, database permissions, account administration, configuration, and backup arrangements. External providers have responsibilities for their own services.

An assessment of TechDex's defined service boundary would not, by itself, certify a customer's entire infrastructure. These responsibilities must be documented before making broader assurance claims.

ISO/IEC 27001 and SOC 2

ISO/IEC 27001 concerns an organization's information security management system within a defined scope, including people, processes, and technology. SOC 2 involves an independent examination and report on controls over a defined service system. Application tests contribute evidence to readiness work; they do not replace either independent process.

The appropriate assurance route will be selected according to customer requirements and the service scope. Any future certification or examination status will be reported with its actual scope and supporting details.