Trust Center

Security at StrikeCore

StrikeCore is built with defense-in-depth principles. Below is how we protect license data, customer accounts, and software distribution.

Signed License Envelopes

Every license is cryptographically signed using an RSA key pair held only by the license server. Teamservers validate the signature locally before trusting any license, and the public key can be embedded in customer binaries.

Seat Enforcement

Licenses include a maximum number of teamserver seats. Activations are recorded per machine fingerprint, preventing casual redistribution and giving customers visibility into active deployments.

Audit Logging

Administrative actions, customer portal logins, password resets, license operations, and update distribution events are recorded in a dedicated audit log. Logs include actor type, action, target, IP address, user agent, and timestamp.

Update Integrity

Update packages are stored with SHA-256 hashes. Downloads include the hash in a response header so teams can verify package integrity before installation. Tampered packages are rejected automatically.

Role-Based Admin Access

The admin console supports role separation. Superadmin accounts manage system-level configuration, while admin, support, and sales roles receive only the permissions required for their responsibilities.

Customer Two-Factor Authentication

Customer portal accounts can enable TOTP-based two-factor authentication. Even if a password is compromised, account access still requires a time-based one-time code from an authenticator app.

Responsible Disclosure

Found a security issue in StrikeCore? Email security@example.com with details. We commit to acknowledging reports within 72 hours and resolving verified issues promptly. We do not pursue legal action against researchers who follow responsible disclosure practices.

Security Questions

For security-related inquiries, account compromise reports, or compliance questions, contact us through the Contact page.