Security
A security vendor that is vague about its own posture is answering the question. This page states what is true today, including what is not yet in place.
Current posture, stated plainly
BMC Operations LLC is an early-stage company. We hold no third-party security certification — no SOC 2, no ISO 27001, no penetration test report from an external firm. We will say so on this page until it changes. If a procurement process requires certification today, we do not meet it, and we would rather you knew that before a call than after one.
Architecture, and why it limits exposure
Crucible is primarily a tool you run yourself. The engine, CLI and dashboard execute inside your own infrastructure, against your own endpoints, writing evidence to your own storage. In that mode no transcript, no canary and no finding ever reaches us.
That is a deliberate design choice, not an accident of being early. The least risky way to handle a customer’s adversarial transcripts is not to hold them.
How sensitive material is handled
Canaries and system prompts
Before anything is written to disk, canary values and the declared system prompt are replaced with SHA-256 digests. The evidence ledger never contains a live secret.
Transcripts
A transcript can contain a leaked canary, because that leak is the finding. Reports mask declared canary values by default, and every disclosure finding carries a remediation step instructing rotation.
Evidence integrity
Every recorded event is hashed over its own content and its predecessor’s hash. Altering, inserting or removing an entry invalidates every hash after it, and crucible verify reports the exact entry at which a chain breaks. Each run publishes a root hash you can anchor externally.
Model providers
When you configure an LLM adversary or judge, prompts and transcripts are sent to that provider under your own account and their terms. The deterministic mode sends nothing anywhere, which is why it is the default.
Reporting a vulnerability
Email security@crucible.langes.fun. Please include reproduction steps and give us reasonable time to remediate before publishing.
We will acknowledge within five business days. We do not currently operate a paid bounty programme, and we will not pretend otherwise. We are glad to credit researchers publicly.
We will not pursue legal action against good-faith research that respects user privacy, avoids degrading our services, and does not access data beyond what is needed to demonstrate the issue.
Scope
In scope: crucible.langes.fun and the Crucible codebase. Out of scope: findings produced by Crucible against your own systems (those are yours to triage), third-party services we link to, and reports generated solely by automated scanners without a demonstrated impact.
Last updated 2026-10-07. These documents are published by BMC Operations LLC and are provided for transparency. They are not legal advice.