Skip to content
Vendor.sh

Theme

Palette

Your own colour

Saved for this browser, on every page.

Security

What we built, what proves it, and what we do not claim.

Every control on this page names the test or the class that makes it true. The limits are written down too, because a missing sentence reads like a promise.

composer test:security
  • PASS WorkspaceIsolationSweepTest
  • PASS PublicSurfaceCanaryTest
  • PASS StructuredOutputStrictModeTest
  • PASS SourceMapsAreNeverShippedTest
  • PASS SettingsManagementTest
Controls are run, not described Illustrative output

Implemented

Controls, each with the thing that proves it.

Controls, each with the thing that proves it.
Control What it means for you Proved by
Workspace isolation Separate workspaces and projects limit cross-workspace access. WorkspaceIsolationSweepTest
Limited service keys A project key has abilities, a deployment allowlist, an expiry and revocation. ProjectServiceKeyManager
Connections kept out of content Provider and tool credentials stay outside public workflow content. ProjectConnectionManager
Restricted outbound calls Workflow calls to the network go through a restricted URL policy. UrlGuard unit tests
Human approval A workflow can pause until an eligible member reviews it. ProjectWorkflowApprovalManager
No secrets in run results Public run resources omit secret connection material. WorkflowRunResource contract tests
Checked model output Structured output is validated against its schema before anything acts on it. StructuredOutputStrictModeTest
Encrypted settings and keys Settings and provider keys are encrypted at rest and never logged. SettingsManagementTest

Who we defend against

Who we defend against, from our threat model.

Naming who we defend against is what makes a gap visible. The threat model lists each one, the control that answers it, and the test that makes it fire.

The open internet

Rate limits, CSRF protection, and embed sessions that carry a hashed token.

Covered by a test

Another tenant

Every query scoped to a workspace; keys never cross one.

Covered by a test

A member acting badly

Server-side permission checks on every action.

Covered by a test

What the model returns

Output checked against a schema before anything acts on it.

Covered by a test

The supply chain

Audited installs and no source maps shipped.

Covered by a test

Someone with database access

Settings and provider keys encrypted at rest.

Covered by a test

Not claimed

Said plainly, so nobody assumes otherwise.

  • No compliance certification — not SOC 2, ISO 27001, HIPAA or PCI DSS.
  • No published uptime figure.
  • No penetration-test result.
  • No promise about model training beyond each provider’s own terms.
  • No data retention guarantee.

Found something?

Tell us privately first.

Use the contact form and put “Security” in the first line. Include what you found and how to reproduce it. Please do not open a public issue about a weakness that is not fixed yet.

  1. Describe the issue and the affected page or endpoint
  2. Share the steps to reproduce it
  3. Keep it private until we have answered
Report a vulnerability

Ask about a control this page does not cover.

Confirm every assurance you need before you use the platform in production.

A person reads it and replies to the email you gave