Security Overview
Our architectural guarantees for sandbox isolation, token protection, and network safety.
Every PR verification run boots a single-tenant Docker container for the app under test, capped on memory, CPU and PIDs, with all capabilities dropped (plus DAC_OVERRIDE) and no-new-privileges set. The container is created on demand and removed with --rm when the run completes.
External verification and developer tools strictly enforce IP denylisting. Loopback ranges (127.0.0.0/8), RFC1918 private subnets, link-local addresses (169.254.169.254 cloud metadata), and multicast pools are blocked at the DNS and socket levels before any HTTP connection is established.
Test-user credentials are encrypted at rest with AES-256-GCM using a key supplied out-of-band via CREDENTIAL_STORE_KEY (required when running in production). Credentials are injected into the sandbox as environment variables at boot and are excluded from intent logs, LLM prompts, and generated remediation text.
All dashboard routes enforce strict CSP headers, restricting script executions, blocking unsafe inline code injections, and locking frame ancestors to prevent clickjacking.
© 2026 RazeQA Platform. All rights reserved.