Tracework

Security

Security boundaries

Tracework keeps its learning environment deliberately constrained. This page describes current controls without claiming certification or a formal bug-bounty program.

Private-beta draft · Last reviewed July 25, 2026

Current controls

  • The terminal maps supported commands to deterministic fixtures and never starts a host shell.
  • KQL runs against scenario fixtures, not a live SIEM or external target.
  • Protected routes validate server sessions and investigation ownership.
  • Authentication and investigation endpoints are rate limited, and production uses secure, HTTP-only cookies.
  • Grading rules and answer material remain server-side, with security headers applied at the application edge.

Responsible reporting

Do not include passwords, session tokens, private keys, employer information, or live incident data in a report. Do not test production beyond your normal learner account without written authorization.

The reporting address and acknowledgement target will be published before private-beta invitations are sent.

Current limitations

Tracework has not claimed an external security certification, service level agreement, or public vulnerability-reward program. Production monitoring and incident ownership must be confirmed before the first learner is invited.

Contact

Contact details will be published before private-beta invitations are sent.