Security that survives
a lost laptop.
Workspaces live in the cloud, keys live in the Agent, and secrets never touch disk. Every connection is authenticated, every action is recorded, and access can be revoked the moment a device goes missing.
Zero-trust access
ed25519 keys, no shared passwords, no inbound ports.
Secrets vault
Encrypted at rest, injected by reference, never logged.
Immutable audit
Append-only record of every session and change.
Instant revocation
Kill a stolen device’s access in one click.
Zero-trust by construction
The OpusFocus Agent holds your ed25519 key and opens outbound-only tunnels to your workspaces. There are no inbound ports on the laptop, no VPN to misconfigure, and no shared credentials to leak.
- ed25519 key auth — Per-developer keys; no passwords anywhere in the path
- Outbound tunnels — Workspaces are never directly exposed to the internet
- Short-lived sessions — Tunnels expire and re-handshake; no standing access
A Vault-lite for every workspace
Store credentials once and inject them into workspaces by reference. Secrets are encrypted at rest, mounted as environment variables at runtime, and never rendered in the UI, logs or snapshots.
- Reference injection — ${secret:db_url} resolves at boot, never stored in the template
- Encrypted at rest — AES-256 envelope encryption with per-workspace data keys
- Redaction everywhere — Values masked in UI, terminal scrollback and audit log
An immutable record of everything
Every SSH login, container attach, package install, snapshot and access decision is written to an append-only log. It's the foundation for compliance evidence, approval workflows and session recording.
- Append-only — Tamper-evident hash chain; entries can’t be edited or deleted
- Full coverage — Workspace, container, secret-access and policy events
- Exportable — Stream to your SIEM or pull SOC 2 evidence on demand
Revoke a stolen laptop in one click
Group developers, scope templates and set who can reach which workspaces. When a device is lost, revoke its keys and every tunnel drops immediately — the work is safe in the cloud, the laptop is now worthless.
- Role & group scoping — Least-privilege access mapped to teams and templates
- Instant key revocation — One click invalidates the device; sessions terminate at once
- Approval workflows — Gate sensitive workspaces behind a second approver
Audited, certified, accountable
Independent attestation across the controls platform teams are asked about in every security review.
Bring your security team
the easy answer.
Whitepaper, SOC 2 report and a live audit-log demo — everything a review needs in one packet.