PageSourceSearch

https://currents.dev/_next/static/chunks/pages/security-c1e6b790adb33936.js

js currents.dev collected 2026-09-25 20:49:44 UTC 18,188 bytes, 5 lines download raw bytes

1(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[8338],{30508:(e,n,i)=>{(window.__NEXT_P=window.__NEXT_P||[]).push(["/security",function(){return i(69074)}])},31172:(e,n,i)=>{"use strict";i.d(n,{V:()=>a});var r=i(37876),s=i(14232),t=i(76816);let a=s.forwardRef(({toc:e=!0,children:n},i)=>(0,r.jsx)(r.Fragment,{children:(0,r.jsx)("div",{className:"mx-auto px-4 lg:px-8 max-w-[1400px]",children:(0,r.jsxs)("div",{className:"flex justify-center flex-col md:flex-row-reverse md:gap-12 lg:gap-16",children:[e&&(0,r.jsx)("aside",{className:"hidden md:block md:w-48 lg:w-56 flex-shrink-0 md:pr-4 lg:pr-8",children:(0,r.jsx)("div",{className:"sticky top-[120px]",children:(0,r.jsx)("div",{className:"overflow-y-auto max-h-[calc(100vh-160px)] pr-2",children:(0,r.jsx)("div",{className:"text-sm",children:(0,r.jsx)(t.D,{})})})})}),(0,r.jsx)("div",{ref:i,className:"flex-1 min-w-0",children:(0,r.jsx)("article",{className:"prose prose-invert container pt-24 pb-8",children:n})})]})})}));a.displayName="BlogPostLayout"},69074:(e,n,i)=>{"use strict";i.r(n),i.d(n,{default:()=>d});var r=i(37876),s=i(91668),t=i(88610),a=i(54587),o=i.n(a);let l=({children:e})=>(0,r.jsx)(t.b,{children:e});function c(e){let n={a:"a",em:"em",h1:"h1",h2:"h2",h3:"h3",li:"li",p:"p",span:"span",ul:"ul",...(0,s.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsxs)(n.h1,{id:"security-and-trust",children:["Security and Trust",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#security-and-trust",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:(0,r.jsx)(n.em,{children:"Last Revised: March 13, 2025"})}),"\n",(0,r.jsx)(n.p,{children:"We appreciate and value our customer's trust - the quality and security of our systems are important aspects of our everyday practices."}),"\n",(0,r.jsxs)(n.h2,{id:"compliance",children:["Compliance",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#compliance",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsxs)(n.h3,{id:"soc2-compliance",children:["SOC2 Compliance",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#soc2-compliance",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"Currents achieved SOC2 Type 2 compliance in March 2025. The SOC2 report is an independent third-party examination report that demonstrates how Currents addresses key security principles and criteria. Our SOC2 report is available upon request, please use the link below to request a copy."}),"\n",(0,r.jsxs)("div",{className:"mx-auto w-full flex justify-center flex-col items-center py-4",children:[(0,r.jsx)("div",{children:(0,r.jsx)(o(),{className:"text-center",src:"/img/soc2.png",width:120,height:120,alt:"SOC2 Compliance Logo"})}),(0,r.jsx)("div",{className:"text-center",children:(0,r.jsx)("a",{href:"https://compliance.currents.dev/",target:"_blank",children:(0,r.jsx)(n.p,{children:"Currents Trust Center (by Vanta)"})})})]}),"\n",(0,r.jsxs)(n.h3,{id:"csa-star-level-1",children:["CSA STAR Level 1",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#csa-star-level-1",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"Cloud Security Alliance, the Security Trust Assurance and Risk (STAR) registry encompasses key principles of transparency, rigorous auditing, and cloud security and privacy best practices. Our CSA CAIQ 4.1 self-assessment questionnaire, which is based on the Cloud Controls Matrix and the CSA Code of Conduct for GDPR Compliance, is available for your convenience."}),"\n",(0,r.jsxs)("div",{className:"mx-auto w-full flex justify-center flex-col items-center py-4",children:[(0,r.jsx)("div",{children:(0,r.jsx)(o(),{className:"text-center",src:"/img/STAR-Level-1.svg",width:120,height:120,alt:"STAR-Level-1 Certification Logo"})}),(0,r.jsx)("div",{className:"text-center",children:(0,r.jsx)("a",{href:"https://cloudsecurityalliance.org/star/registry/services/currents-dev",target:"_blank",children:(0,r.jsx)(n.p,{children:"Currents.dev CSA CAIQ 3.1 Level 1 Listing"})})})]}),"\n",(0,r.jsxs)(n.h2,{id:"eu-customers",children:["EU Customers",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#eu-customers",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)("a",{href:"https://prighter.com/q/15737831043",target:"_blank",children:(0,r.jsx)("img",{style:{margin:"0 auto"},width:"200",src:"https://prighter.com/certificateofrepresentation/15737831043/getwebcertificate.png",alt:"Prighter certificate of Art 27 representation"})}),"\n",(0,r.jsx)(n.p,{children:"We value your privacy and your rights as a data subject and have therefore appointed Prighter as our privacy representative and 
1your point of contact."}),"\n",(0,r.jsxs)(n.p,{children:["Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative Prighter or make use of your data subject rights, please visit: ",(0,r.jsx)(n.a,{href:"https://prighter.com/q/15737831043",children:"https://prighter.com/q/15737831043"})]}),"\n",(0,r.jsxs)(n.h2,{id:"product-security",children:["Product Security",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#product-security",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"We are committed to using the industry's best practices and controls to ensure that we provide secure and reliable service to our customers."}),"\n",(0,r.jsxs)(n.h3,{id:"authentication",children:["Authentication",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#authentication",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"We use AWS Cognito to store and authenticate our Services' users - the credentials are only available to users and are never exposed to our personnel."}),"\n",(0,r.jsxs)(n.h3,{id:"permissions",children:["Permissions",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#permissions",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"We enable permission levels within the app to be set for your teammates. Permissions can be set to include app settings, billing, and performing critical activities."}),"\n",(0,r.jsxs)(n.h3,{id:"password-and-credential-storage",children:["Password and Credential Storage",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#password-and-credential-storage",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"The credentials and authentication logic are protected by a well-known and established vendor."}),"\n",(0,r.jsxs)(n.h3,{id:"uptime",children:["Uptime",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#uptime",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsxs)(n.p,{children:["We have an uptime of 99.8% or higher. Our status page is available at ",(0,r.jsx)(n.a,{href:"https://status.currents.dev",children:"status.currents.dev"}),"."]}),"\n",(0,r.jsxs)(n.h2,{id:"network-and-application-security",children:["Network and application security",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#network-and-application-security",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsxs)(n.h3,{id:"data-hosting-and-storage",children:["Data Hosting and Storage",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#data-hosting-and-storage",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"Currents services and data are hosted in Amazon Web Services (AWS) facilities (us-east-1) in the USA."}),"\n",(0,r.jsxs)(n.h3,{id:"failover-and-dr",children:["Failover and DR",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#failover-and-dr",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"Currents was built with disaster recovery in mind. All of our infrastructure and data are spread across 2 AWS availability zones and will continue to work should any one of those data centers fail."}),"\n",(0,r.jsxs)(n.h3,{id:"virtual-private-cloud",children:["Virtual Private Cloud",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#virtual-private-cloud",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"All of our servers are within our own virtual private cloud (VPC) with network access control lists (ACLs) that prevent unauthorized requests from getting to our internal network."}),"\n",(0,r.jsxs)(n.h3,{id:"back-ups-and-monitoring",children:["Back Ups and Monitoring",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#back-ups-and-monitoring",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"We do utilize periodic backups of customer data and service metadata to ensure reliable recovery if needed."}),"\n",(0,r.jsxs)(n.h3,{id:"permissions-and-authentication",children:["Permissions and Authentication",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#permissions-and-authentication",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"Access to customer data is limited to authorized employees who require it for their job. Currents is served 100% over https."}),"\n",(0,r.jsx)(n.p,{children:"We have SAML Single Sign-on (SSO), 2-factor authentication (2FA), and strong password policies on GitHub, Google, AWS, and MongoDB to ensure access to 3rd party services is protected."}),"\n",(0,r.jsxs)(n.h3,{id:"encryption",children:["Encryption",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#encryption",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"All data sent to or from Currents is encrypted in transit using 256 bit encryption. Our API and application endpoints are TLS/SSL only. We also encrypt data at rest using an industry-standard AES-256 encryption algorithm."}),"\n",(0,r.jsxs)(n.h3,{id:"pentests-and-vulnerability-scanning",children:["Pentests and Vulnerability Scanning",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#pentests-and-vulnerability-scanning",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"Currents uses third-party security tools to periodically scan for vulnerabilities on application and network layers."}),"\n",(0,r.jsxs)(n.h2,{id:"vulnerability-disclosure",children:["Vulnerability Disclosure",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#vulnerability-disclosure",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"The disclosure of security vulnerabilities helps us ensure the security and privacy of our users. We encourage security researchers to report any security vulnerabilities they find to us."}),"\n",(0,r.jsxs)(n.h3,{id:"rules-of-engagement",children:["Rules of Engagement",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#rules-of-engagement",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"Security researchers must not:"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:"disclose vulnerability information except as set forth in the ‘Reporting a Vulnerability’ and ‘Disclosure’ sections below,"}),"\n",(0,r.jsx)(n.li,{children:"engage in social engineering,"}),"\n",(0,r.jsx)(n.li,{children:"send unsolicited electronic mail to Currents users, including “phishing” messages,"}),"\n",(0,r.jsx)(n.li,{children:"execute or attempt to execute “Denial of Service” or “Resource Exhaustion” attacks,"}
1),"\n",(0,r.jsx)(n.li,{children:"introduce malicious software,"}),"\n",(0,r.jsx)(n.li,{children:"test in a manner which could degrade the operation of Currents systems; or intentionally impair, disrupt, or disable Currents systems,"}),"\n",(0,r.jsx)(n.li,{children:"test third-party applications, websites, or services that integrate with or link to or from Currents systems,"}),"\n",(0,r.jsx)(n.li,{children:"delete, alter, share, retain, or destroy Currents data, or render Currents data inaccessible, or,"}),"\n",(0,r.jsx)(n.li,{children:"use an exploit to exfiltrate data, establish command line access, establish a - persistent presence on Currents systems, or “pivot” to other HHS systems."}),"\n"]}),"\n",(0,r.jsxs)(n.h3,{id:"reporting-a-vulnerability",children:["Reporting a Vulnerability",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#reporting-a-vulnerability",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsxs)(n.p,{children:["We accept vulnerability reports at ",(0,r.jsx)(n.a,{href:"mailto:[email protected]",children:"[email protected]"}),". Reports may be submitted anonymously."]}),"\n",(0,r.jsx)(n.p,{children:"Information submitted will be used for defensive purposes only – to mitigate or remediate vulnerabilities. If your findings include newly discovered vulnerabilities that affect all users of a product or service and not solely Currents, we may share your report with other organizations where it will be handled under their coordinated vulnerability disclosure process. We will not share your name or contact information without express permission."}),"\n",(0,r.jsx)(n.p,{children:"By sending a report you are indicating that you have read, understand, and agree to the guidelines described in this policy for the conduct of security research and disclosure of vulnerabilities or indicators of vulnerabilities related to Currents systems, and consent to having the contents of the communication and follow-up communications."}),"\n",(0,r.jsx)(n.p,{children:"In order to help us triage and prioritize submissions, we recommend that your reports:"}),"\n",(0,r.jsxs)(n.ul,{children:["\n",(0,r.jsx)(n.li,{children:"Describe the vulnerability, where it was discovered, and the potential impact of exploitation."}),"\n",(0,r.jsx)(n.li,{children:"Offer a detailed description of the steps needed to reproduce the vulnerability (proof of concept scripts or screenshots are helpful)."}),"\n"]}),"\n",(0,r.jsxs)(n.h3,{id:"disclosure",children:["Disclosure",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#disclosure",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsx)(n.p,{children:"Currents is committed to timely correction of vulnerabilities. However, we recognize that public disclosure of a vulnerability in absence of a readily available corrective action likely increases versus decreases risk."}),"\n",(0,r.jsx)(n.p,{children:"Accordingly, we require that you refrain from sharing information about discovered vulnerabilities for 90 calendar days after you have received our acknowledgement of receipt of your report. If you believe others should be informed of the vulnerability prior to our implementation of corrective actions, we require that you coordinate in advance with us."}),"\n",(0,r.jsxs)(n.h2,{id:"have-any-questions",children:["Have any questions?",(0,r.jsx)(n.a,{"aria-hidden":"true",tabIndex:"-1",href:"#have-any-questions",children:(0,r.jsx)(n.span,{className:"icon icon-link"})})]}),"\n",(0,r.jsxs)(n.p,{children:["If you have any questions (or comments) concerning this document, please send us an email to the following address: ",(0,r.jsx)(n.a,{href:"mailto:[email protected]",children:"[email protected]"})," and we will make an effort to reply within a reasonable timeframe."]})]})}function d(e={}){return(0,r.jsx)(l,{...e,children:(0,r.jsx)(c,{...e})})}},76816:(e,n,i)=>{"use strict";i.d(n,{D:()=>t});var r=i(37876),s=i(14232);let t=()=>{let{toc:e,activeId:n}=(()=>{let[e,n]=(0,s.useState)([]),[i,r]=(0,s.useState)(null);return(0,s.useEffect)(()=>
1{let e=null,i=null,s=!1,t=()=>Array.from(document.querySelectorAll("article.prose h2")),a=()=>{let i=t();return 0!==i.length&&(n(i.map((e,n)=>{let i=e.id||`heading-${n}`;return e.id=i,{id:i,text:e.textContent,tag:e.tagName.toLowerCase(),level:parseInt(e.tagName[1])}})),(e=()=>{let e=t();if(0===e.length)return;let n=null,i=1/0;for(let r of e){let e=r.getBoundingClientRect(),s=Math.abs(e.top);e.top<=300&&s<i&&(i=s,n=r)}n&&r(n.id)})(),window.addEventListener("scroll",e,{passive:!0}),s=!0,!0)};a()||(i=new MutationObserver(()=>{a()&&(i?.disconnect(),i=null)})).observe(document.body,{childList:!0,subtree:!0});let o=requestAnimationFrame(()=>{s||(a(),i?.disconnect(),i=null)});return()=>{cancelAnimationFrame(o),i?.disconnect(),e&&window.removeEventListener("scroll",e)}},[]),{toc:e,activeId:i}})();return(0,r.jsxs)("nav",{className:"toc","aria-label":"Table of Contents",children:[(0,r.jsx)("div",{className:"mb-5",children:(0,r.jsx)("div",{className:"text-xs font-semibold text-dark-500 uppercase tracking-widest letter-spacing",children:"On This Page"})}),(0,r.jsx)("ul",{className:"space-y-0",children:e.map((e,i)=>{let s=n===e.id;return(0,r.jsx)("li",{className:"list-none",children:(0,r.jsx)("a",{href:`#${e.id}`,onClick:n=>{var i;let r;return i=e.id,n.preventDefault(),void((r=document.getElementById(i))&&r.scrollIntoView({behavior:"smooth",block:"start"}))},className:`
2                  block transition-all duration-200 pl-0 text-sm leading-relaxed py-2.5
3                  ${s?"text-emerald-400 font-semibold border-l-2 border-emerald-400 ml-0 pl-3":`text-dark-400 border-l-2 border-transparent ml-0 pl-3
4                         hover:text-emerald-300 hover:border-emerald-400/50`}
5                `,children:e.text})},i)})})]})}},88610:(e,n,i)=>{"use strict";i.d(n,{b:()=>o,u:()=>l});var r=i(37876),s=i(31172),t=i(37539),a=i(89505);let o=s.V,l=e=>(0,r.jsxs)(r.Fragment,{children:[(0,r.jsx)(a.F,{opaque:!0}),(0,r.jsx)(s.V,{...e,toc:!0}),(0,r.jsx)(t.A,{})]})},91668:(e,n,i)=>{"use strict";i.d(n,{R:()=>a,x:()=>o});var r=i(14232);let s={},t=r.createContext(s);function a(e){let n=r.useContext(t);return r.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function o(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:a(e.components),r.createElement(t.Provider,{value:n},e.children)}}},e=>{e.O(0,[5587,3557,3471,4587,3843,636,6593,8792],()=>e(e.s=30508)),_N_E=e.O()}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.