End-to-endEach organization has a 256-bit org key that exists only on your clients. It reaches your browser, daemons, and CI machines as P-256 sealed-box grants; the server stores ciphertext it cannot open.
At restSecret values are AES-256-GCM envelopes (96-bit nonces, 128-bit tags) encrypted client-side under the org key before they are sent to us.
Context bindingEvery ciphertext is bound to its secret and environment via associated data - rows cannot be swapped in storage undetected.
Key rotationOrg keys rotate client-side: an admin’s browser re-encrypts every value under a fresh key and re-grants it to active devices in one atomic change. Lost passphrases recover via a one-time recovery code.
Passwords & machine secretsArgon2id (64 MiB, 3 iterations), versioned parameters, constant-time verification. Refresh and invitation tokens are stored only as SHA-256 hashes.
In transitTLS 1.3 to the platform; local daemon-to-SDK delivery over a unix socket (macOS/Linux) or named pipe (Windows) with user-only permissions.
Sessions15-minute access tokens, rotating refresh tokens, org-configurable absolute session expiry, per-device revocation.