Security model
Credentials
- Encrypted at rest with AES-256-GCM: a random nonce per encryption, an authentication tag, and associated data that binds each ciphertext to its secret and owner. The master key is held only in the hosting platform’s encrypted environment, never in the database or source code.
- No endpoint returns a stored credential: not to agents, not to the owner. Deleting a secret erases the ciphertext and stops its policies and leases immediately.
- The credential is decrypted only inside a single proxied request. Its buffer is zeroed after use; the copies the HTTP client needs (header or query string) live only for that request.
- Upstream responses are scanned for the credential (raw, URL-encoded, base64, JSON-escaped) and every match is replaced with
[REDACTED]. Compressed responses are decoded first so the scan is complete. - Credentials, Authorization headers, request/response bodies and query strings are never logged, audited or sent to monitoring.
Agents and leases
- Agent tokens are random and MAC-protected; only a SHA-256 hash is stored. Tokens can be rotated and revoked; revoking an agent revokes its leases.
- A policy binds exactly one agent to exactly one secret (no wildcards). Lease length and request count can never exceed the policy; the current policy is enforced on every request.
- Expiry is evaluated on every read and use; there is no background job to miss.
Proxy (SSRF protection)
- Only https:// on port 443 to DNS hostnames on the policy’s allowlist (exact match). IP-address URLs and internal names (localhost, *.internal, *.local …) are refused.
- Every address the hostname resolves to is checked when the connection opens, and the socket connects to the checked address (no DNS-rebinding window). Loopback, private, CGNAT, link-local, cloud metadata (169.254.169.254), multicast, reserved and IPv4-embedding IPv6 ranges are blocked.
- Redirects are never followed. Responses are capped at 1 MB and requests at 64 KB; upstream calls time out after 15 s.
- Agents cannot set Authorization, Cookie, Host, Proxy-*, X-Forwarded-* or the credential’s own header.
Accounts
- Passwordless sign-in with single-use links that expire in 15 minutes. Sessions use HttpOnly, Secure, SameSite=Strict cookies; state-changing requests must come from this origin.
- Rate limits apply to sign-in, lease creation and proxied requests. Every lease, request, denial, revocation and payment is in the owner’s audit log.