Security Model v2.4
Infrastructure Security

Security Overview

Our architectural guarantees for sandbox isolation, token protection, and network safety.

Containerized Sandbox Isolation

Every PR verification run boots a single-tenant Docker container for the app under test, capped on memory, CPU and PIDs, with all capabilities dropped (plus DAC_OVERRIDE) and no-new-privileges set. The container is created on demand and removed with --rm when the run completes.

SSRF Mitigation & Safe Network Egress

External verification and developer tools strictly enforce IP denylisting. Loopback ranges (127.0.0.0/8), RFC1918 private subnets, link-local addresses (169.254.169.254 cloud metadata), and multicast pools are blocked at the DNS and socket levels before any HTTP connection is established.

Encrypted Credential Storage

Test-user credentials are encrypted at rest with AES-256-GCM using a key supplied out-of-band via CREDENTIAL_STORE_KEY (required when running in production). Credentials are injected into the sandbox as environment variables at boot and are excluded from intent logs, LLM prompts, and generated remediation text.

Strict Content Security Policy (CSP)

All dashboard routes enforce strict CSP headers, restricting script executions, blocking unsafe inline code injections, and locking frame ancestors to prevent clickjacking.

© 2026 RazeQA Platform. All rights reserved.