Security
Last updated: April 3, 2026.
Decoda RWA Guard is built for operational trust: workspace-scoped access control, audit visibility, and resilient behavior across live and degraded dependencies.
Core controls
- Role-based workspace access with owner/admin/analyst/viewer scopes.
- Session management, CSRF protection, and multi-factor authentication — mandatory for every human user of a Pilot workspace, configurable elsewhere.
- Audit logs for workspace administration and workflow-critical actions.
- HTTPS transport in deployed environments, terminated by the deployment platform; Decoda application code does not set the TLS version or cipher policy.
- Workspace secrets encrypted with AES-256-GCM under a managed, versioned application key; passwords hashed with salted scrypt.
Security reporting
To report a security concern, email security@decodasecurity.com with reproduction details and affected environment information. For non-security support, use Support.
Shared responsibility
Customers are responsible for user lifecycle management, workspace role assignment, and integration credential hygiene. Decoda is responsible for service operation, infrastructure hardening, and response communication.