Security you can show with confidence
Credentials are vaulted, scoped, and withdrawn when the case ends.
- Web-root access only — never root on the server
- Encrypted secrets at rest (AES-256-GCM)
- Access withdrawn after the job completes
- Audit log for terms acceptance and every apply approval
- Verified backup before every live write
- SSH uses allowlisted diagnostic commands only — no open shell
Secrets are encrypted with AES-256-GCM. They are never shown in clear text again after storage.