Review scope
DetCordon treats every request body, header, path, filename, network frame, and sample as hostile. Security review covers containment, resource exhaustion, evidence integrity, source attribution, operator-data exposure, and privileged cleanup behavior.
The current review is a targeted source and generated-configuration review. It is not a formal penetration test or a claim that arbitrary malware is safe.
Closure standard
A security finding closes only when the implementation enforces the boundary, a regression test proves rejection, and generated deployment defaults agree. Documentation-only mitigation does not close a finding.
Implemented controls include bounded hostile inputs and aggregate request budgets, handle-based file capture, tenant evidence partition checks, proxy normalization, bounded listener admission, encrypted sample storage, and offline-verifiable evidence bundles.
Open hardening work remains explicitly gated from managed-production claims. Current areas include authenticated source identity, process-tree termination, and fail-closed remote service configuration. Detailed findings and remediation evidence are available during qualified diligence.
Responsible disclosure
Do not publish proof-of-concept payloads, sample bodies, credentials, or customer identifiers. Use the RAGBAZ contact path with the subject “DetCordon security disclosure” to establish a private reporting channel. Include only the affected component, deployment assumptions, observed impact, and the minimum material required to reproduce the issue.