Security
Secrets, encryption at rest, the network, access control and hardening for an OCI deployment.
Secrets
AUTH_SECRETsigns sessions;ENCRYPTION_KEYencrypts stored credentials. Both at least 32 characters, different from each other, generated randomly (openssl rand -base64 48), and kept in a secret manager.- Credentials are write-only. Provider keys, SMTP passwords, S3 keys, search keys, single sign-on secrets and certificates, connector credentials, people's connector tokens and webhook secrets are encrypted with
ENCRYPTION_KEYand never returned by the dashboard or the API. - The audit log records whether a secret was set, cleared or replaced, never its value.
- Rotating
ENCRYPTION_KEYinvalidates every stored credential. Do not rotate it casually, and never as part of a rollback.
Network
- Serve OCI over HTTPS only, behind a TLS proxy, and set
APP_URLto thehttps://address. AddStrict-Transport-Securityat the proxy. - The web container sends a strict Content Security Policy,
X-Frame-Options: DENYand other headers; see Reverse proxy. Keep the artifact frame's separate policy intact. - Keep PostgreSQL, Redis, the API port and
/metricsoff the public network. Only the web container needs to be reachable. - Client addresses in the audit log, on sessions and in the sign-in limit come from the web container, which trusts nothing in front of it unless you list your proxies in
TRUSTED_PROXIES. Set it behind a load balancer or ingress, and never route/apiaround the web container. See Reverse proxy. - Sign-in attempts are limited per client address and per account (
RATE_LIMIT_AUTH_PER_MINUTE, 10 a minute by default). See Budgets and limits. - Outbound requests are guarded. Connectors and webhooks refuse private, loopback, link-local and other reserved addresses unless an administrator allows a private network for that one connector or endpoint, always refuse cloud metadata addresses, never follow redirects, and are size- and time-limited. Identity providers on private networks must be listed in
AUTH_TRUSTED_ORIGINS. - Model provider and search addresses are set by administrators and are not restricted to public addresses.
Access
- Make group mapping an access boundary: turn on Require a matching role for your identity provider, or everybody it authenticates gets in. See Identity.
- Trust for account linking only for a provider that really verifies email ownership.
- Keep one verified local administrator with a known password for break-glass access, and test
/auth/login?local=1. - Use the
auditorrole for compliance reviewers instead ofadmin. - Sessions are cached for up to five minutes per API replica, so revoking a session, banning or changing a role can take that long to reach every replica.
- There is no multi-factor authentication for local accounts in v0.10.2; rely on your identity provider's MFA, and keep local accounts to break-glass administrators.
Content
- Model replies are rendered as sanitised Markdown; following a link to another site asks for confirmation first.
- HTML and SVG artifacts run in a sandboxed frame with an opaque origin and no network access.
- Uploads are checked by content, not file name, and logos refuse SVG.
- Share links never include reasoning, attachments or project content, and deleting a conversation revokes them for good. People can see and revoke all their links under Settings → Sharing, also after sharing is turned off for them.
Data
- Conversation content never enters the audit log, metrics, traces or webhooks.
- The compliance export copies content only if an administrator turns that on.
- Retention, legal hold and the trash are described under Retention and Compliance. Every deletion is recorded in the audit log (what, whose, by whom and why, never the content), and a legal hold pauses every deletion of a held person's records.
Images
- The API image runs as the non-root
ociuser. - Pin images to a version, or better a digest. Read Releases before upgrading.
Reporting a vulnerability
Follow the security policy in the OCI repository.