Least privilege, by default
Access is granted to the people who need it, to the systems they need, for as long as they need it, and no further. Permissions are reviewed regularly and revoked the moment they are no longer needed.
Cedar Noctua's own security follows a consistent set of principles. Cedar Noctua holds itself to the same standard it sets for clients.
Access is granted to the people who need it, to the systems they need, for as long as they need it, and no further. Permissions are reviewed regularly and revoked the moment they are no longer needed.
Identity is the perimeter of a modern company. Cedar Noctua centralizes authentication through an identity provider with single sign-on across business applications and multi-factor authentication enforced on every account, with phishing-resistant MFA wherever the application supports it.
Mail leaving cedarnoctua.com is authenticated to the standards major mailbox providers now require. Impersonation attempts are rejected before they reach an inbox. The configuration is monitored continuously.
No single control carries the weight of the entire security program. Controls are layered so that a failure in one is caught by the next, and the overall posture does not depend on any single tool or boundary holding.
Every tool, integration, and exposed service must justify its presence. What is not needed is not deployed. The result is an environment that is simpler to operate, easier to audit, and harder to compromise.
If you have found a security issue affecting Cedar Noctua, write to security@cedarnoctua.com. Cedar Noctua's security.txt is available at /.well-known/security.txt.