Trust Center

Operational guarantees & security posture

Resonance is designed for production incident response. This hub summarises the controls already in-place—security headers, signed desktop payloads, transparent updates—and where to escalate questions.

Security Baseline

Strict Content Security Policy, HSTS, frame protections, and hardened cookies mirror OWASP best practices across every page load.

View security baseline

Signed Desktop Agent

Platform binaries ship with signing + notarisation guidance for macOS, Authenticode for Windows, and GPG for Linux plus staged auto-update manifests.

Review signing guide

Auto-Update Safeguards

Incremental updates are SHA256 verified, staged, and never applied silently—operators choose when to promote a download.

Inspect update workflow

Security in depth

Every deployment inherits the baseline documented above: TLS-only session cookies, constant-time API key checks, and CSP rules that explicitly admit Intercom, Stripe, and Resonance-controlled origins. Dashboard releases are versioned and tagged; the agent exposes version metadata so you can confirm what is running directly from the UI. Export a JSON/CSV health snapshot from the dashboard Overview to capture the same data for audits.

Desktop agent protections

  • • SHA256 manifest published alongside every build artifact.
  • • macOS notarisation + hardened runtime, Windows Authenticode signing.
  • • Linux packaging hooks for post-install + post-remove checks.

Platform runtime controls

  • • Rate limiting gracefully degrades when Redis is unavailable—no crash loops.
  • • Auth cookies configured with Secure, HttpOnly, and SameSite=Lax in production.
  • • CSP forbids third-party execution outside vetted analytics & support tooling.

Contact & escalation

For urgent issues you can page the operations desk directly. Non-urgent security questions are triaged within one business day.

Incident response: ops@resonance.dev — 24/7 pager for production-impacting events
Security disclosures: security@resonance.dev — PGP key fingerprint 3F8A 1C24 9BA5 0C12
Status page: https://status.resonance.dev (mirrors uptime feed from dashboard export)