Defensive public boundary

Security

CASCA treats every provider payload as hostile data, exposes only the Caddy edge, and separates acquisition, parsing, writing, derivation, and read-only web access.

Report a vulnerability

Email admin@lanzalabs.io with a concise description and safe reproduction steps. Do not send exploit payloads, credentials, customer data, active scanning results, or destructive proof-of-concept content.

Scope and handling

Architecture minimum

PostgreSQL and worker services are private; the web role is read-only; query and graph resources are capped; containers have no Docker socket; releases are allowlisted, scanned, checksummed, immutable, and reversible.