Skip to content

Security

Trust rules

Nobody should run an unknown program on a production server unless these rules hold. They are part of the product, and no feature is worth breaking one.

It never changes a file, a setting or a container. It prints the fix, and you run it.

The agent’s code is published at release, so anyone can read what it does before installing it. Until then, what the agent reads and sends lists every file it reads and everything it sends.

A one-off scan sends nothing off the server. Data leaves only after you connect the server, which a later release adds.

The agent reports that a secret exists and where, never its value. Passwords in logs and connection settings are masked on the server.

The agent opens no port and accepts no incoming connection.

One command uninstalls it. One click deletes a server’s history.

Logs, errors and findings go only to the service’s own storage.

These hold for the hosted dashboard when it arrives.

  1. Two-step sign-in is required for every teammate, in the dashboard and in the terminal.
  2. Each token does one job. A server token can only send results. A deploy token can only mark deploys. Neither can read data.
  3. Every action is recorded in the activity log: who assigned, muted, invited or changed what.
  4. Every request is checked against the person’s role and access, on the server. Anything hidden from them answers as not found.

What the agent reads and sends lists every file and setting a scan reads. It is built from the same file the agent uses.