Skip to content

Security and data

This page lists behaviors that run in the live product.
It does not invent retention days, a deletion portal, or a customer audit-log screen.

Sign-in

The dashboard uses PropelAuth.
You sign in with the email an admin stored on Users.

Lab auth bypass is not a customer sign-in method.

Roles

The Users form can assign admin, user, viewer, manager, and analyst.

Only these roles can change Configurations, Alerting, and Users:

  • admin
  • administrator
  • support
  • support_admin

Other signed-in users see View only on those pages.
You cannot change your own role.

Data you enter

On Configurations you store:

  • Domains and keywords
  • Integration match rules (host, path, or string)
  • Vendor name, domain, and critical flag

On Users you store name, email, phone, and role.
On Alerting you store destination type, label, endpoint URL, and rule thresholds.

Secrets

Exposures are secret-level rows (type, file, repository, severity).
The exposure list can show file preview context.

Alert webhooks do not include the recoverable secret value.
See Alerting.

Secret values can be stored with Vault transit encryption when that mode is on for the tenant.
When that mode is off, the customer API stores the value without transit.

Alerts

A matching report sends HTTP POST to your destination.
HTTP status below 400 counts as success. Other results record failure.

Delivery is stored as an alert event (sent, partial, or failed).
The live sidebar has no Alert events page.

API request log

The customer API writes an audit row for /v1/ requests.
A row includes actor, path, method, status, duration, client IP, user agent, and request id.
Health and docs paths are skipped.

There is no Audit page in the dashboard sidebar.

What this page does not claim

  • A published retention period
  • A self-serve delete-all-my-data flow
  • SSO products other than PropelAuth sign-in
  • That a vendor grade is an impact decision