WND customer portal

WND customer portal: security summary

For security reviewers. The portal is where your IT team downloads WND Terminal and manages who at your company can. WND Terminal itself doesn't depend on it: installed copies keep working whatever happens to the portal.

Who can get in

  • Invitation only: your company's portal admins (or WND) invite people, in two roles, Admin and Downloader. The one exception is a switch your admins control: with your company login connected, they can let in anyone your login lets through, as a Downloader.
  • Sign-in is by a one-time code sent to the work email, or your own company login (SAML: Okta, Microsoft Entra ID and others). There are no portal passwords.
  • Your admins can require your company login for your verified email domains (proven by a DNS record), so removing someone from your directory stops them signing in again. A company login can only sign in addresses at its own verified domains.
  • Sessions last 12 hours. Removing a person in the portal, or the end of your contract, signs them out at once.
  • Each sign-in has to finish in the browser that started it, and the person must come back as the same sign-in identity.
  • Sign-in attempts are rate-limited per address and per network; the address gets an email if its sign-in is paused.
  • WND staff use a separate console with a second factor (an authenticator app). Staff can't sign in as your people, and anything staff change on your account, invitations included, shows in your activity.

The installers

  • Built by our build pipeline and stored in private storage that only the pipeline can write to; each release is stored once and never overwritten.
  • Every file has a published SHA-256 checksum on the downloads page.
  • The portal only publishes a release to the stable channel when our build pipeline has marked it code-signed (Windows) and notarized by Apple (Mac). Preview builds are labeled as previews.
  • Each download link works for 10 minutes and only for the person who clicked it, so links can't be passed around.

What we store, and where

Your companyName, email domains, seats, contract dates, single sign-on settings.
Your peopleName, work email, role, last sign-in. No passwords, no payment details.
ActivitySign-ins and refused sign-ins, invitations, role and single sign-on changes, contract changes and downloads: who, what, when, and from which IP address. Kept for 2 years, then deleted.
WhereThe portal, its database and the installer storage run on Cloudflare in the United States. Sign-in is handled by Kinde (United States) and emails are sent by Resend (United States).

Your portal admins can see your company's activity and export it as CSV at any time.

In the browser

  • HTTPS only, with strict security headers (a content security policy, no framing).
  • No third-party scripts, analytics or trackers on portal pages.

Questions

For our security pack or to report a security issue, contact us.