Skip to content
superCharged

Security

Built so operators can keep privileged access tight

superCharged supports NIS2 Article 21 cybersecurity risk-management measures for covered entities. NIS2 binds the organisation that runs the client — not the desktop app. This page is the supplier evidence pack: what the product does, and what it does not claim.

Claim

Supports Article 21. Not a compliance badge.

There is no EU product certificate called NIS2-compliant for an SSH client. Procurement should treat superCharged as ICT that implements access, secret-hygiene, and supply-chain measures you can map into your own programme.

  • We never say the product or Aurora is NIS2 certified or NIS2 compliant.
  • Covered entities remain responsible for policies, incident reporting, MFA where appropriate, and supplier contracts.
  • Ask for this page plus the in-app Help Security topic when filling a supplier questionnaire.

Article 21 map

ICT measures already in the client

Each row is current product behaviour. Use it as evidence, not as a substitute for your organisation controls.

NIS2 Article 21 themes mapped to superCharged behaviour
ThemeProduct behaviourOperator effect
Access controlSign-in required per unlocked catalogue source. Rights come from that source (NetBox user, phpIPAM app, KeePass vault).Operators only see devices their unlocked sources allow.
Authentication / credentialsUsername/password and KeePass master password stay in process memory for this run only. Never written to disk.Closing the app drops secrets. Nothing to steal from the settings file.
Cryptography / secrets hygieneNetBox: auto-provisioned token, maximum one-day lifetime, prior superCharged tokens revoked on sign-in.Old client tokens do not stay valid after the next login.
Supply chain / ICT acquisitionNo telemetry. Documented outbound allow-list including the Windows package feed. Catalogues from operator-configured sources only.Firewall teams can list exactly which hosts the client may contact.
Asset managementDevices load from NetBox, phpIPAM, and/or a local KeePass database — not a second invented inventory.The operator catalogue stays the source of truth.
Basic cyber hygieneNo credential vault on disk. No plugin phone-home. Idle lock can wipe the session. Local session audit log records opens without secrets.Operators can show auditors what was opened, without storing passwords.

Supplier questionnaire

Answers procurement usually asks

Where are passwords stored?
Nowhere. Username/password and KeePass master password stay in process memory for this run only. Closing the app clears them.
How are API tokens handled?
Each sign-in provisions a NetBox token (max one day) and revokes prior superCharged auto-provisioned tokens for that user. Manual NetBox tokens are left alone.
Is there telemetry?
No. The client contacts unlocked catalogue URLs (NetBox / phpIPAM), SSH to devices you open, optional IPMI HTTPS, local WinBox on this computer, and on Windows the package feed. KeePass is a local file. No analytics phone-home.
How do we report a vulnerability?
Email contact@auroratech.ai with a description and reproduction. Do not file public issues with exploit detail.

Operator docsSupplier questionnaire