Provider Monitoring · Contents
Provider Monitoring

Security model & privacy

Encryption, scoping, and why Breaklytix never sees your keys.

  • Authentication: GitHub OAuth only; no passwords stored.
  • Tokens: encrypted at rest with Fernet (TOKEN_ENCRYPTION_KEY); never exposed to the browser.
  • Session: short-lived signed JWT issued after OAuth callback.
  • Data scoping: every query filters by the authenticated user (or agency client).
  • Debug/introspection endpoints require the internal secret and are disabled for external callers.
  • Email delivery logs exclude message content and secrets.

Full details live in the Security page and Privacy Policy linked in the footer.

Related articles
Privacy PolicyTerms of Service