SemantiqWall
PT EN
Sign in I'm a vendor
Secure by Design

How SemantiqWall follows the 7 Secure by Design goals

The Secure by Design Pledge is a public commitment for software manufacturers created by CISA, the US Cybersecurity and Infrastructure Security Agency. This page shows, goal by goal, what we already do and what's still in progress.

Updated on 09/28/2026. This page is not a certification: it's our public account, which you can check in the product itself.

1

Multi-factor authentication (MFA) Done

MFA is required for every user and can't be turned off. Approving a critical agent action asks for the code again, even with an active session.

Next step: passkeys, which resist phishing.

2

No default passwords Done

There are no default passwords and no open sign-up. Every account starts with a unique temporary password that expires in 72 hours and must be changed at first sign-in. Passwords have at least 12 characters with upper- and lowercase letters and numbers, and sign-in attempts are rate-limited.

3

Eliminating entire classes of vulnerability Done

Database queries are always parameterized; HTML is escaped automatically; a Content Security Policy forbids inline scripts and styles; every form is protected against CSRF; third-party websites are only fetched through a client that blocks internal addresses (SSRF); and per-organization isolation rejects any query without an organization set.

Next step: publish the product's threat model.

4

Security patches In progress

SemantiqWall is a cloud service: a fix reaches every customer the same day, with no action on their part.

In progress: per-version security advisories for the PHP and TypeScript SDKs, which customers install.

5

Vulnerability disclosure policy Done

A public policy with scope, testing rules, response times and safe harbor for good-faith researchers, plus the contact in /.well-known/security.txt.

See the policy

6

Vulnerability transparency (CVE) In progress

Published commitment: critical or high-severity flaws affecting customers become a public advisory with the weakness type (CWE) and, where applicable, a CVE ID.

In progress: no advisories published so far; the first one will follow this format.

See the policy

7

Evidence of intrusions Done

Every customer gets, at no extra cost, an append-only, hash-chained audit trail: sign-ins and failed attempts, MFA, configuration changes, API keys and the decision on every AI agent action. Customers can verify the trail's integrity themselves in the dashboard.

See our security program policies in the Trust Center

Source of the goals: CISA Secure by Design Pledge.