Skip to content

Security boundary · human authority · auditability

Smohix Security

Security posture

Smohix is designed so control evidence, approvals, and automation safeguards stay visible by default — a controlled operations model, not unrestricted execution.

Trust boundary

Controlled operations model

High-impact changes require explicit approvals, dry-run context, and policy checks before execution. This reduces unsafe direct execution paths and supports stronger operational review.

  • Approval checkpoints for high-risk actions
  • Dry-run and policy enforcement before automation
  • Auditable incident, approval, and automation history
  • Connector health visibility before workflows proceed

Control planes

Boundaries you can inspect

Each plane summarizes an existing control area. Claims stay limited to what Smohix actually ships — formal certifications are not asserted here.

  • Identity boundary

    Access & credentials

    Protected
    Who can reach console routes and programmatic APIs.
    Control
    Supabase Auth for console sessions. Smohix API keys and ingest tokens for scoped machine access.
    Developer authentication →
  • Data boundary

    Secrets & workspace scope

    Protected
    Where credentials and tenant data are allowed to live.
    Control
    Server-side environment secrets only. Workspace data scoped by Supabase RLS and org membership.
    Trust evidence →
  • Execution boundary

    Controlled operations

    Protected
    What high-impact automation can do before a human decides.
    Control
    Approval checkpoints, dry-run context, and policy checks before guarded execution.
    Approvals (signed in) →
  • Human authority

    Human-in-the-loop control

    Protected
    Where people remain accountable for consequential change.
    Control
    High-impact automation waits for an explicit approval record — Copilot assists; it does not bypass governance.
    Platform overview →
  • Audit boundary

    Traceability

    Protected
    What operational history is retained for review.
    Control
    Auditable incident, approval, and automation event history designed for exportable review.
    Audit log (signed in) →
  • API boundary

    Endpoint hardening

    Protected
    How public and operational HTTP surfaces are constrained.
    Control
    Security headers, restricted indexing, no-store/noindex for sensitive runtime metadata, rate limits on sensitive routes.
    API security docs →

Transport & disclosure

Domain posture and reporting

Domain and transport

Production metadata and canonical links are anchored to the apex domain smohix.run. Requests to www hosts redirect to the canonical apex to avoid split-origin behavior.

Vulnerability disclosure

If you believe you identified a vulnerability, report it privately to hi@smohix.run. Include reproduction steps, affected endpoints, and potential impact. We triage reports promptly and coordinate remediation and customer communication as needed.

Additional assurance detail: Trust & governance · repository SECURITY.md