Security & Governance

Access and credential controls, described honestly

These are product capabilities and intended controls. They are not a claim of any certification, audit, or regulatory compliance.

Implemented

Credential Storage

Endpoint connection secrets are stored through the portal's secret store rather than kept in plain configuration.

Implemented

Authenticated Portal

The management portal requires sign-in; the public marketing pages are the only anonymous surface.

Implemented

Multi-Factor Authentication

Portal accounts can enable TOTP-based MFA for an additional sign-in factor.

Implemented

Role-Based Access Control

A role and permission model scopes access to resources by action (view, create, edit, execute, approve).

Planned

Audit Visibility

Centralised, exportable audit trails across projects and jobs are planned.

Planned

Data Residency Controls

Region and residency configuration is planned and not yet available.

Important: These describe product capabilities and intended controls. They are not a claim of any specific certification, audit, or regulatory compliance.