Reference
Security model
How accounts, credentials, organizations and deployments are kept apart, and what is encrypted.
Accounts and sessions
- Passwords are stored as salted scrypt hashes. Passkeys (WebAuthn) can replace them at sign-in.
id.dev.gov.vinissues ES256-signed access tokens to the platform's own apps through OAuth 2.1 with PKCE. Access tokens last 15 minutes; refresh tokens rotate on every use. See Sign-in and sessions.- Each app keeps its tokens in
HttpOnly,Secure, host-only cookies. Deployments run underdeployments.dev.gov.vin, a different domain, so customer code never receives them. - The API accepts an access token only when it was issued to one of the platform's apps.
Permissions
Every API route, MCP tool and Git operation checks a scope in the organization it acts on. People get scopes from their role; keys get exactly the scopes chosen when they were created, and only scopes their creator holds. Platform administration checks scopes in the platform organization.
Credentials
| Credential | Stored as | |
|---|---|---|
Keys (si_mcp_, si_api_, si_agent_) | SHA-256 hash | Shown once. Optional expiry. Revoking takes effect on the next request. |
Agent device tokens (si_dev_) | SHA-256 hash | Issued at approval; revoked by removing the device. |
| Environment variables | KMS ciphertext | Bound to their organization and project with a KMS encryption context. Sensitive values are never returned. |
| Connector credentials | KMS ciphertext | Bound to their organization and connector. Never returned. |
| Cloudflare token | KMS ciphertext | Bound to its organization. Never returned. |
The KMS key rotates automatically. Transferring a project to another organization re-encrypts its variables for that organization.
Isolation between organizations
- Storage. Every database and bucket is named with its organization's prefix. API routes act only on records of the organization in the path, and check the AWS name is inside that organization's prefix.
- Server functions. Each organization's deployments run with their own execution role, which reaches only that organization's tables and buckets (plus logs). Linking decides which names a project's code is given; it doesn't widen access.
- Builds. Each build gets credentials valid for one hour that reach only its own repository, its own deployment's output and its project's build cache. The build machine's own role can only write logs. See Builds.
- Hostnames. Each deployment has its own hostname. Custom domains can't be added under
gov.vin, and a hostname belongs to one project at a time.
Data at rest
- Buckets block all public access and are encrypted at rest. Files are reached through your app or presigned links.
- Databases are created with deletion protection on; it has to be turned off before a table can be deleted.
- Knowledge page content, deployment artifacts and build caches are stored in the platform's own encrypted S3 buckets.
Outbound requests
- Connectors reach only
httpsURLs whose every address is public. The hostname is checked when the URL is saved and again on every connection, so a DNS change can't point it at internal hosts. - Self-hosted agents reach only hosts on their allowlist; anything else waits for approval in Cloud.
Deployments are public
Production and preview hostnames serve anyone who has the URL. Deployment hostnames are hard to guess but not secret; protect sensitive routes in your app.
Audit
Changes to projects, domains, keys, members, resources, connectors, agents and settings are recorded in the organization's audit log, with who made them and from where.