Summary
This Knowledge Base article provides information on Neverfail's policy regarding cyber security. UPDATED: August 2026.
Neverfail takes security very seriously. In light of many of the news worthily incidents (and the thousands more we don’t hear about) surrounding trojan horse hacks and ransomware, Neverfail continues to tighten its security posture with its software.
Neverfail Engine provides users with the highest level of protection that enables IT administrators to recover from continuity events very quickly.
Latest Security Updates and Fixes for OpenJDK, Apache Tomcat, Log4j
Engine's objective is to keep your systems up, running, protected, and safe. Having the latest security updates, fixes and patches for the used open-source software is critical. Current GA release is updated to:
Software Integrity & Release Verification
- Compliance: SBOM is now available for this release to provide transparency into the bundled components and their dependencies.
- Downloadable SBOMs (CycloneDX) are available in EMS for current GA version of Engine components.
- Added missing component supplier information (required by NTIA).
- Added verification pack containing the digital signatures and public key required to verify the integrity and authenticity of the Engine SBOMs.
- Integrity & Verification: A separate .sha256 sidecar file is provided alongside each .msi installer for download checksum verification.
- Build-Time Binary Authenticity: All compiled binaries (.exe, .dll) are digitally signed at build time using an EV Code Signing Certificate (Neverfail, LLC), and final .msi installer packages are signed prior to distribution.
Recovery from Malware and Ransomware
Neverfail Engine establishes a process to ensure IT administrators can recover from malware and ransomware attacks due to its cluster architecture. Engine firewalls each node in the cluster. This means the Neverfail Channel connection is restricted to only Engine communications like replication, application and system monitoring. It also provides robust snapshots / data rollback module on each node in the cluster to ensure corrupted data is protected and recoverable on each firewalled node. This is a core value proportion of Engine where it protects the most critical applications.
Harden Engine
Snapshots / Data Rollback
Neverfail Engine’s Snapshots (also known as Data Rollback Module) helps avoid problems associated with corrupt data, by enabling data rollback to an earlier snapshot (shadow copy) / point-in-time, if data corruption occur. Snapshots feature configuration is explained in
How to Setup Data Snapshots / Rollback for Neverfail Engine.
Third Party Software
Neverfail Engine uses 3rd party software resources such as
Apache Tomcat web services. Neverfail periodically upgrades Tomcat services in its production releases. This ensures we have the latest security patches available. Although our product releases do not coincide with Apache Tomcat, every effort is made to update Engine to reflect the latest security fixes.
In addition, Neverfail using OpenJDK in its core. Java is the primary automation tool Engine uses for orchestration of failover tasks. Achieving our acceptable/targeted/minimal baseline security standards includes periodic upgrades its distribution of OpenJDK. Each upgrade includes patches for security vulnerabilities.
Due to the fact that 80% of Engine core functions are centered around OpenJDK and that Engine limits storage of credentials, penetration testing is limited to once per year or at a major version release. We do not disclose the results of those test for security reasons. As mentioned, security vulnerabilities are remediated via periodic upgrades from OpenJDK and Apache Tomcat and Log4j.
HSTS Enablement
Encryption
Encryption is updated to industry standard.
Two Factor Authentication
In the near future, Engine will integrate two factor authentication and eventually MFA into the Engine Management Service (EMS). This will add industry wide best practices for securing user level authentication to Engine.
Code Access
Neverfail strive to secure our product while in development. We limit who as access to source code and build repositories. Strict security protocols are enforced. We also support stringent log management policies in our engineering department to properly audit access and provide accountability.
Applies To
Neverfail Engine