Security
Security boundaries
Tracework keeps its learning environment deliberately constrained. This page describes current controls without claiming certification or a formal bug-bounty program.
Private-beta draft · Last reviewed July 25, 2026
Current controls
- The terminal maps supported commands to deterministic fixtures and never starts a host shell.
- KQL runs against scenario fixtures, not a live SIEM or external target.
- Protected routes validate server sessions and investigation ownership.
- Authentication and investigation endpoints are rate limited, and production uses secure, HTTP-only cookies.
- Grading rules and answer material remain server-side, with security headers applied at the application edge.
Responsible reporting
Do not include passwords, session tokens, private keys, employer information, or live incident data in a report. Do not test production beyond your normal learner account without written authorization.
The reporting address and acknowledgement target will be published before private-beta invitations are sent.
Current limitations
Tracework has not claimed an external security certification, service level agreement, or public vulnerability-reward program. Production monitoring and incident ownership must be confirmed before the first learner is invited.
Contact
Contact details will be published before private-beta invitations are sent.