Security controls

Security and access controls in Dashmon

This page focuses on the technical controls inside Dashmon: MFA with recovery codes, workspace-specific OIDC / SSO, admin step-up verification, scoped API tokens, audit visibility, and responsible disclosure. For procurement, legal, privacy, and broader customer review, use the Trust Center.

MFA / 2FAWorkspace SSOAudit logsAPI token governance

Authentication

Local and Google sign-in, MFA / 2FA challenges with recovery codes, workspace-specific OIDC / SSO, time-limited password resets, and progressive temporary lockouts.

Admin protection

Sensitive admin views are protected behind admin access checks and additional one-time verification before platform-wide or billing-sensitive workflows are shown.

Governance

Labeled API tokens, access scopes, expiry, recent-use visibility, request tracing, account security activity, shared-workspace governance, and blocked-action auditing.

Current posture

What Dashmon is already doing

Access controls

Protected app and API areas, premium feature gating, admin-only routes, owner-only governance boundaries, delegated workspace controls, and additional verification for platform-wide admin workflows.

Security headers

CSP, HSTS, referrer-policy, nosniff, permissions-policy, and noindex controls for private surfaces help reduce accidental exposure.

Sensitive event tracking

Dashmon records sign-in activity, MFA and recovery-code events, token changes, admin verification, billing-sensitive actions, and protected changes for later review.

Disclosure route

A public security.txt endpoint is available for responsible disclosure and contact details.

Clear boundaries

Current limitations to be aware of

Enterprise identity is live today

Dashmon supports MFA with recovery codes, workspace-specific OIDC / SSO, SSO enforcement, domain restrictions, required or denied group policy, and role-aware workspace access.

External validation still matters

Dashmon exposes practical controls and public trust material, but long-term reliability evidence, broader compliance proof, and external security review or penetration testing should still be part of production go-live planning.

Customer review

Security controls covered on this page

Use this page for authentication, workspace identity, admin protection, API token governance, audit visibility, and disclosure controls. Use the Trust Center when the review also needs privacy, legal, operational-readiness, or procurement material.

Security & access overview

Review this page for MFA, workspace OIDC / SSO, audit visibility, admin verification, and responsible disclosure.

Privacy and terms

Use public privacy and terms pages for data handling, service expectations, billing, and acceptable use questions.

API docs and support paths

API authentication, request tracing, and shared-workspace behavior are documented publicly, and Help Center points customers to the fastest next step.

Trust pack

Customer trust pack and security review path

What the trust pack covers

Public security page, privacy policy, terms, contact details, help-center guidance, API docs, and a generated security.txt preview.

What still stays internal

Detailed audit exports, restore proof, release evidence, dependency review output, and internal compliance artifacts should be shared separately after disclosure review.

For procurement or security-review requests that need a curated bundle, use contact so Dashmon can share the right pack safely.

Trust & company

Product trust should be easy to verify.

Security, privacy, legal terms, operational trust and company information remain separate so each topic stays clear and specific.