Designed to pass your vendor risk review
Mainframe sessions carry credentials and customer records. WND Terminal is built so that none of it ever leaves your network, and so your security team can verify that.
Customer-hosted only
We ship software, not a service. Your host traffic, user IDs and screen data never pass through WND Software systems.
Validated encryption
TLS 1.2 and 1.3 implemented through a FIPS 140-3 validated cryptographic module. Client certificate and smart-card authentication from the Windows store.
Signed and inspectable
Every MSI is code-signed. Every release ships with a software bill of materials (SBOM) so you can track every component.
Secure development
Practices mapped to the NIST Secure Software Development Framework, including a written policy on AI-assisted coding, automated dependency and licence scanning, and fuzz testing of the protocol engine.
Privacy-safe diagnostics
The flight recorder redacts screen contents by default. Support never needs to see customer data to find a problem.
No phone-home
Licences are verified offline from a signed file. No telemetry is sent unless you turn it on, and there is no remote kill switch.
Documentation for your review
Available under NDA to organizations evaluating WND Terminal:
- Standardized questionnaire responses (SIG Lite)
- Secure development policy and NIST SSDF mapping
- Architecture and data-flow description
- SBOM for the current release
- Vulnerability disclosure policy and patch timelines
- Accessibility conformance report (VPAT)
- Source code escrow arrangements
Reporting a vulnerability
If you believe you’ve found a security issue in a WND Software product, email [email protected] with “Security report” in the subject. We acknowledge reports within two business days and will keep you informed until the issue is resolved. Please don’t test against systems you don’t own.
Start with a security conversation
Many evaluations begin with the security team. We’re happy to walk yours through the architecture before anything is installed.