Agent Reference

Everything an AI agent needs to know about Uwitz Corporate.

This page is machine-readable. It describes our company, products, services, API, and how to interact with us.

Overview

Uwitz Corporate is the commercial arm of the Uwitz organization. We develop, deploy, and support commercial security software, and provide professional security services.

Domain: uwitz.co
Tagline: Commercial security engineering for teams that cannot outsource their trust.
Nonprofit arm: uwitz.org

Products

All products are described in detail at /products.

Irys SSO

Identity and access platform with OIDC, SAML, WebAuthn, and server agents for IDS/IPS. Integrated with Microsoft Entra ID (Azure AD). Used for internal staff authentication across Uwitz systems.

Proprietary Code Development

Bespoke software built for client organisations, tailored to their systems and security requirements. Proprietary, closed-source code delivered under contract.

Managed Infrastructure

Supported deployment of Uwitz security products. Includes setup, monitoring, and ongoing support.

Services

All services are described at /services.

  • Security Audits — Comprehensive security assessments of your infrastructure and applications
  • Penetration Testing — Controlled adversarial testing to find vulnerabilities before attackers do
  • Proprietary Code Development — Bespoke software built to your organisation's needs and systems
  • Deployment Engineering — Expert deployment of security tools and infrastructure
  • Support Contracts — Ongoing technical support from the engineers who build the tools

Site Pages

/
Homepage — company overview and value proposition
/products
Product catalog — Irys SSO, managed infra, proprietary code development
/services
Professional services — audits, pentesting, deployment
/about — Company structure and commitments
/contact
Contact channels — sales, support, security, billing
/billing
Make a payment by card (Stripe) or bank transfer
/privacy
Privacy policy — data collection and processing
/terms
Terms of service and vulnerability disclosure policy
/ai
This page — AI agent reference

API Endpoints

Public

POST/api/create-payment-intent
Create a Stripe payment. Accepts: amount (cents, $1–$500k), paymentMethodId (Stripe pm_*), frequency ("once" or "monthly"), reference (invoice ref, 3–64 chars). Returns: { clientSecret }.
Auth: None (public)
POST/api/webhook
Stripe webhook receiver. Handles payment_intent.succeeded, payment_intent.payment_failed, and subscription lifecycle events. Requires Stripe signature verification.
Auth: Stripe signature header
POST/api/session-token
Generate a signed session token. Body: { email, role }. Returns: { token }. Token is HMAC-SHA256 signed, expires in 24 hours.
Auth: None
POST/api/oidc/token
Exchange OIDC authorization code for tokens. Body: { provider, code, redirectUri }. Currently supports: entraid (Microsoft Entra ID). Client secrets are kept server-side.
Auth: None

Admin (require Bearer token)

GET/api/admin/dashboard
Summary metrics: MRR, outstanding invoices, active subscriptions, total customers, 10 most recent invoices.
Auth: Bearer token (admin/staff role)
GET/api/admin/invoices
List invoices. Query: status (open/paid/overdue/draft/all), starting_after, limit (max 100).
GET/api/admin/invoices/:id
Invoice detail with line items, charges, payment intent.
POST/api/admin/invoices
Create invoice. Body: { customer, amount, description, metadata }.
POST/api/admin/invoices/:id/pay
Pay/settle invoice. Body: { payment_method_id } (optional).
POST/api/admin/invoices/:id/refund
Issue refund. Body: { amount, reason }. Reason options: duplicate, fraudulent, requested_by_customer.
POST/api/admin/invoices/:id/send
Resend invoice email to customer via Stripe.
GET/api/admin/subscriptions
List subscriptions. Query: status (active/past_due/canceled/all), starting_after, limit.
GET/api/admin/subscriptions/:id
Subscription detail with plan, amount, period, latest invoice.
POST/api/admin/subscriptions/:id/update
Update subscription. Body: { quantity, metadata }.
POST/api/admin/subscriptions/:id/cancel
Cancel subscription. Body: { at_period_end: boolean }.
GET/api/admin/customers
List customers. Query: query (search), starting_after, limit.
GET/api/admin/customers/:id
Customer detail with subscriptions, invoices, payment methods.
POST/api/admin/customers
Create customer. Body: { email, name, metadata }.
GET/api/admin/payments
List payment intents. Query: status (succeeded/processing/failed/all), starting_after, limit.
GET/api/admin/payments/:id
Payment intent detail with charges.
POST/api/admin/settle
Settle an invoice. Body: { invoice_id, payment_method_id }.

Contact

hello@uwitz.co
General enquiries, sales, support, billing
security@uwitz.co
Vulnerability reports (reaches engineering directly)

Phone: +1 (774) 304-6439

Address: Uwitz Corporate Ltd.

Company Structure

{
  "organization": "Uwitz",
  "entities": [
    {
      "name": "Uwitz",
      "type": "nonprofit",
      "domain": "uwitz.org",
      "role": "Open-source tooling, research, education"
    },
    {
      "name": "Uwitz Corporate",
      "type": "commercial",
      "domain": "uwitz.co",
      "role": "Services, support contracts"
    }
  ],
  "relationship": "Uwitz Corporate is the commercial arm of Uwitz. It develops, deploys, and supports commercial security software."
}

Technical Details

{
  "runtime": "Node.js + Express",
  "auth": {
    "staff": "Irys SSO (OAuth 2.0) + Entra ID (OIDC)",
    "admin_api": "HMAC-SHA256 signed Bearer tokens, 24h expiry",
    "local_fallback": "PBKDF2-SHA512 password verification"
  },
  "payments": {
    "provider": "Stripe",
    "methods": ["card"],
    "types": ["one-time", "monthly retainer"],
    "limits": { "min_cents": 100, "max_cents": 50000000 }
  },
  "design_system": "Custom CSS (Geist fonts, dark theme, CSS variables)",
  "cdn": "Fastly",
  "tls": "ML-DSA-87 post-quantum signatures",
  "ci_cd": "GitLab CI at git.uwz/corporate/website",
  "data_processing": {
    "stripe": "Payment processing (card data never touches our servers)",
    "irys": "Staff authentication",
    "entraid": "Staff authentication (Azure AD)"
  }
}

Resources for Agents

Machine-Readable Formats