← Back to Documentation

Security

Security controls informed by ISO 27001 principles

Disclaimer: Controls are informed by ISO 27001 principles. This is not certification or audit.
DESIGN REFERENCE

ISO 27001 Alignment

Controls designed with reference to ISO/IEC 27001:2022 Annex A.

ISO 27001 Annex A Mapping

Note: This is a non-exhaustive subset of selected controls. A full Statement of Applicability (SoA) is maintained internally for enterprise due diligence requests.

Annex A ControlImplementation
A.5.1 Security policiesTerms, Privacy Policy, AGB
A.5.15 Access controlAPI key auth (X-API-Key header), rate limits
A.5.23 Cloud securityEU residency, Cloudflare, TLS
A.5.28 Evidence collectionOn-chain attestations, DAP hashes
A.8.9 Configuration mgmtVersioned APIs, systemd, nginx
A.8.13 BackupDaily encrypted, cross-server sync
A.8.15 LoggingRequest IDs, access logs, monitoring
A.8.20 Network securityTLS 1.2+, HSTS, CSP, firewall
A.8.24 CryptographySHA-256, TLS, on-chain anchors
A.8.26 App securityInput validation, rate limiting

Security Headers

HeaderStatus
Strict-Transport-Security
X-Frame-Options
X-Content-Type-Options
X-XSS-Protection
Referrer-Policy
Permissions-Policy
Content-Security-Policy

Enterprise API Endpoint

Dedicated Enterprise Endpoint: https://api.feedoracle.io
FeatureDetailsStatus
Base URLhttps://api.feedoracle.io
SSL CertificateEdge: Cloudflare-issued · Origin: Let's Encrypt (auto-renewal)
TLS Version1.2+ enforced
Rate Limit10 req/s + burst 20
Max Connections10 concurrent per IP
Data ResidencyGermany (EU)

Transport Security

API Security

Data Protection

Infrastructure

Subprocessors

ProviderPurposeLocation
netcup GmbHServer hostingGermany
CloudflareDDoS, DNS, CDNGlobal (EU config)
ISRG (Let's Encrypt)TLS certificatesUS (automated)

No customer data shared with analytics, advertising, or AI training services.

Data Retention

Key Management

Incident Response

Vulnerability Disclosure Policy

FeedOracle welcomes responsible vulnerability reports from security researchers and the community.

StepDescriptionSLA
1. ReportEmail security@feedoracle.io with description, reproduction steps, and impact assessment
2. AcknowledgementWe confirm receipt and assign a tracking reference48 hours
3. TriageSeverity assessment (Critical / High / Medium / Low)5 business days
4. RemediationFix developed and testedSeverity-dependent
5. DisclosureCoordinated disclosure after fix deployed90 days max
Scope: All *.feedoracle.io domains, public API endpoints, and published client libraries. Out of scope: social engineering, DoS, third-party services (Cloudflare, CDN).

We do not pursue legal action against researchers acting in good faith. Please avoid accessing customer data, disrupting services, or publicly disclosing before coordinated disclosure.

This is not ISO 27001 certification. Organizations responsible for own assessments.

· Trust · Standards