Credential encryption
Integration credentials are encrypted with AES-256-GCM using a derived application key, unique initialization vectors, and authentication tags.
Write-only secrets · Versioned ciphertext
Security & trust
Explore how Undown handles workspace access, protects saved integration credentials, and separates public updates from internal operational data.
Stage 2 of 3
AES-256-GCM uses a derived application key, a fresh initialization vector and an authentication tag to protect the stored credential.
A new IV is generated for each encryption operation.
Current application controls
Integration credentials are encrypted with AES-256-GCM using a derived application key, unique initialization vectors, and authentication tags.
Write-only secrets · Versioned ciphertext
Organization-scoped requests require an authenticated session, active membership, and permission for the requested action.
Membership + permission + scoped query
Owner, administrator, member, and viewer roles separate management privileges from read-only access across workspace resources.
Four workspace roles
Platform changes can retain actor, action, target, request, network, and before/after context while redacting sensitive field names.
Sensitive values redacted
Production authentication uses secure cookies, trusted origins, account-disable checks, and session revocation after password resets.
Secure production cookies
Public status responses use customer-facing component data and derived identifiers without exposing monitor targets or organization records.
Targets remain private
An identity is only the first check
Explore an illustrative request from a workspace viewer. Membership and action permissions determine whether a workspace operation can proceed.
Example actor / Workspace viewer
A viewer can read a monitor in a workspace they belong to.
Demo only. These controls do not access or change a real workspace.
Intentional public boundaries
Public status pages expose customer-facing component information and updates, while private monitor targets and workspace membership stay out of public responses.
Inside the workspace · Fictional example
Public status page · Fictional example
We are investigating checkout errors. Our team is working to restore service and will share an update here.
Customer-facing component name and published update
No monitor target, workspace membership or internal investigation notes.
Data and its purpose
Authentication, organization access, invitations, and support
Accessed through authenticated, role-aware operations
Availability history, incident evidence, charts, and reports
Organization-scoped; historical observations survive region retirement
Deliver notifications to configured destinations
Application-encrypted and never returned in full after storage
Communicate component health, maintenance, and incidents
Explicitly selected content with internal targets removed
Current controls and ongoing work
Current controls are separate from work in progress and planned capabilities. Planned items are not available features or delivery commitments; this page is not a claim of independent certification.
Membership and role permissions are evaluated before workspace data access.
AES-256-GCM protects stored provider credentials at the application layer.
Administrative changes retain traceable context with sensitive-key redaction.
Documented deletion windows and customer-facing retention commitments.
Published severity, escalation, notification, and post-incident commitments.
User-visible active sessions with individual and global revocation controls.
Additional account verification beyond the primary password flow.
SAML-based SSO and automated identity lifecycle management.
Evidence collection and third-party assessment before any certification claim.
Security questions deserve a conversation
Share the affected feature, a description and safe reproduction steps. Please omit passwords, live tokens and customer data from your initial message.