Skip to content

Security

Report a vulnerability

Please report a security problem privately first, through the contact form with the subject "Fadenstack security". Describe what you found and how to reproduce it. Do not open a public issue for it.

How Fadenstack handles data, encryption and access is described on the website's Security and privacy page.

When you build on Fadenstack

  • Keep keys out of code. Read API keys from the environment or a secret store. A key acts with the rights of the user it belongs to.
  • One key per use, and revoke what you don't need. Name each key after the app or script that uses it. Revoke a key in your profile when the app is retired or the key may have leaked; the server refuses it within a minute. Revoking needs a server newer than 0.4.1.
  • Agents sign in per user and device. The SDKs keep an agent's sign-in for the user on that device. The user's password or login token is used once and not kept.
  • Trust the server's certificate. A Fadenstack server often uses its own certificate authority. Install that CA where your application runs, or give it to the SDK, rather than turning certificate checks off.
  • Classify your tools honestly. A tool that changes something is Write or Destructive, so the user is asked first. See Tools and approvals.