Introduction
Amadeus 8 protects doors, credentials and alarm points at banks, hospitals, airports and defense sites, so we treat its own security as part of the product. This page describes how we secure the platform, the controllers and readers it manages, and how to report a vulnerability to us.
Platform security
Amadeus 8 is installed on-premises, on servers and networks the customer controls. There is no cloud dependency: cardholder data, access rules and event logs stay in the customer's own Microsoft SQL Server database.
• Encrypted connections. Client-server and API traffic is supported over HTTPS/TLS.
• Authenticated API. API access requires authentication, with dedicated API user accounts for machine-to-machine integration.
• Password storage. Operator passwords are stored only as SHA-512 hashes, never in plain text.
Controllers and readers
DDS controllers make access decisions locally, so doors keep working correctly if the network or the Amadeus 8 server is unavailable.
• Reader support. Controllers support both Wiegand and OSDP readers.
Operator permissions and audit trail
Each operator works under a profile that sets exactly which screens and functions they can use, and operator activity is recorded.
• Screen-level permissions. Each profile sets every screen to full access, read-only or hidden, and limits which groups and alarm zones the operator can manage.
• Authentication options. Password login with a configurable policy (length, complexity, expiry, history), or Active Directory login.
• Lockout and timeout. Accounts lock after a configurable number of failed logins, and idle sessions log off automatically.
• Audit trail. Logins, failed logins and data changes are recorded with the operator, workstation, time and before/after values.
Secure development and updates
Our R&D team assesses Amadeus 8 the way an attacker would, using the same openly published tools an external red team uses.
• Security testing. We run penetration testing and code review covering static code analysis, dependency scanning with a software bill of materials (SBOM), dynamic API testing, desktop client analysis, service permissions, database configuration, TLS posture, and secret scanning across our full source history.
• Updates. Security fixes are delivered in regular Amadeus 8 releases, announced on the DDS Support Site. We recommend that customers keep their installation on a current version.
Reporting a vulnerability
If you believe you have found a security vulnerability in Amadeus 8, a DDS controller or a DDS reader, please report it to us privately so we can fix it before it is disclosed.
1. Email the security contact below with the product, version, a description of the issue and the steps to reproduce it.
2. We acknowledge your report within 5 business days.
3. We investigate, keep you informed of our progress, and agree a disclosure date with you once a fix is available.
4. With your permission, we publicly credit you for the report.
We ask that you do not test against systems you do not own or are not authorized to test, do not access or modify other people's data, and give us reasonable time to fix the issue before making it public.
Security contact
Email: adiel@dds-security.com
For general technical support, use the DDS Support Site. Product information is at dds-security.com.
Comments
0 comments
Article is closed for comments.