Evidence, not badges

Public security verification

We separate controls that can be independently checked from internal controls that require documentary evidence. We do not describe a control as certified unless an actual certification has been awarded.

Responsible disclosure

Published policy with a dedicated security contact and coordinated disclosure terms.

View evidence

security.txt

Machine-readable security contact for automated discovery.

View evidence

Dependabot

Automated dependency update configuration is present in the repository.

View source evidence

SBOM workflow

A software-bill-of-materials workflow is configured for reproducible evidence.

View source evidence

Externally testable controls

These should be validated using dated external scans and published only when the result is current. External scans are evidence, not penetration tests.

  • HTTPS and TLS configuration
  • HTTP response security headers
  • SPF, DKIM and DMARC
  • DNSSEC and CAA where configured
  • security.txt exposure
  • certificate transparency records

For Group-level governance and assurance documentation, use the Raeburn Group Trust Centre.