Security controls for managed Windows notifications
Toast Notification is designed for MSPs that need tenant isolation, signed endpoint delivery, audit evidence, and clear operational boundaries.
- Notification payloads are signed per tenant with HMAC-SHA256 and verified by the Windows agent before render.
- Tenant-facing API queries are scoped by tenant ID.
- Broadcast-to-all sends require MFA elevation.
- Endpoint configuration is protected with Windows DPAPI.
- Audit records track sends, deliveries, user actions, device registrations, and tenant changes.
For coordinated disclosure or security documentation, contact [email protected].