Security
Built so operators can keep privileged access tight
superCharged supports NIS2 Article 21 cybersecurity risk-management measures for covered entities. NIS2 binds the organisation that runs the client — not the desktop app. This page is the supplier evidence pack: what the product does, and what it does not claim.
Claim
Supports Article 21. Not a compliance badge.
There is no EU product certificate called NIS2-compliant for an SSH client. Procurement should treat superCharged as ICT that implements access, secret-hygiene, and supply-chain measures you can map into your own programme.
- We never say the product or Aurora is NIS2 certified or NIS2 compliant.
- Covered entities remain responsible for policies, incident reporting, MFA where appropriate, and supplier contracts.
- Ask for this page plus the in-app Help Security topic when filling a supplier questionnaire.
Article 21 map
ICT measures already in the client
Each row is current product behaviour. Use it as evidence, not as a substitute for your organisation controls.
| Theme | Product behaviour | Operator effect |
|---|---|---|
| Access control | Sign-in required per unlocked catalogue source. Rights come from that source (NetBox user, phpIPAM app, KeePass vault). | Operators only see devices their unlocked sources allow. |
| Authentication / credentials | Username/password and KeePass master password stay in process memory for this run only. Never written to disk. | Closing the app drops secrets. Nothing to steal from the settings file. |
| Cryptography / secrets hygiene | NetBox: auto-provisioned token, maximum one-day lifetime, prior superCharged tokens revoked on sign-in. | Old client tokens do not stay valid after the next login. |
| Supply chain / ICT acquisition | No telemetry. Documented outbound allow-list including the Windows package feed. Catalogues from operator-configured sources only. | Firewall teams can list exactly which hosts the client may contact. |
| Asset management | Devices load from NetBox, phpIPAM, and/or a local KeePass database — not a second invented inventory. | The operator catalogue stays the source of truth. |
| Basic cyber hygiene | No credential vault on disk. No plugin phone-home. Idle lock can wipe the session. Local session audit log records opens without secrets. | Operators can show auditors what was opened, without storing passwords. |
Supplier questionnaire
Answers procurement usually asks
- Where are passwords stored?
- Nowhere. Username/password and KeePass master password stay in process memory for this run only. Closing the app clears them.
- How are API tokens handled?
- Each sign-in provisions a NetBox token (max one day) and revokes prior superCharged auto-provisioned tokens for that user. Manual NetBox tokens are left alone.
- Is there telemetry?
- No. The client contacts unlocked catalogue URLs (NetBox / phpIPAM), SSH to devices you open, optional IPMI HTTPS, local WinBox on this computer, and on Windows the package feed. KeePass is a local file. No analytics phone-home.
- How do we report a vulnerability?
- Email contact@auroratech.ai with a description and reproduction. Do not file public issues with exploit detail.
