Skip to content

BUILT TO PROTECT / 04

Control belongs
at every layer.

Your packages are your product. The registry limits who can publish, who can install, and how every credential is used.

01

Tenant isolation

Every organization lives behind tenant-scoped queries with PostgreSQL row-level security as a second wall, enforced on every transaction.

02

Credentials

Passwords are hashed with Argon2id; API keys, npm tokens, share links and email tokens are stored as SHA-256 hashes and shown once. Two-factor sign-in, passkeys, SSO and SCIM protect accounts.

03

Encryption at rest

Secrets the application stores for you — SSO client secrets, webhook signing secrets, TOTP secrets — are sealed with authenticated encryption keyed by the installation's encryption key.

04

Package integrity

Published versions are immutable and unpublishing leaves a tombstone. Publish sessions fence concurrent publishers by generation, and request fingerprints reject mismatched replays.

05

Fail-closed delivery

Data planes that serve installs receive short-lived authorization decisions and cache nothing beyond their lease; on an outage they refuse rather than leak.

06

Audit trail

Publishes, license changes, tokens, membership and plan changes are recorded with actor and time in the organization's audit log, kept under your retention settings.

RESPONSIBLE DISCLOSURE

Found something
we should know?

Please report security issues privately using the contact details in our Terms of Service. We investigate every report.