Security posture
ACC treats security as part of trust infrastructure. The current architecture separates public website, API/Core logic, certificate records, object storage, email and administrative controls.
Security posture
This security page explains the current protection model, ledger integrity boundary and responsible disclosure path.
ACC treats security as part of trust infrastructure. The current architecture separates public website, API/Core logic, certificate records, object storage, email and administrative controls.
The current release is not yet a full enterprise SLA environment. Some controls, including partner API keys, webhooks, advanced abuse controls and administrative workflows, may be limited or manually supervised.
Public endpoints use validation and basic abuse controls. Partner and operational endpoints may require administrative or partner keys. ACC may rate-limit, block or investigate traffic that threatens service integrity.
ACC ledger events are designed to preserve payload hashes, previous event hashes, certificate IDs, event types, timestamps, batch roots and anchor status so certificate history can be audited.
Security reports should be sent to info@artclearancecertification.org with the subject 'ACC Security'. Reports should include a description, reproduction steps, impact assessment and contact details.
If ACC identifies a security incident, it will assess scope, protect the system, preserve evidence and notify affected parties or authorities where legally required.