devices.farmSign in

Security

Report vulnerabilities to contact@voxhash.dev. Do not open public issues for security bugs.

  • Per-tenant AES-256-GCM encryption for secrets and task payloads
  • Platform admins cannot unwrap tenant DEKs for your secrets
  • Provider agents authenticate via one-time enrollment tokens
  • Sessions use HTTP-only cookies with JWT verification

Operators: keep USB debugging devices physically secured and use TLS (`wss://`) for providers in production.