Security
Report vulnerabilities to contact@voxhash.dev. Do not open public issues for security bugs.
- Per-tenant AES-256-GCM encryption for secrets and task payloads
- Platform admins cannot unwrap tenant DEKs for your secrets
- Provider agents authenticate via one-time enrollment tokens
- Sessions use HTTP-only cookies with JWT verification
Operators: keep USB debugging devices physically secured and use TLS (`wss://`) for providers in production.