Security & Trust

Security that survives
a lost laptop.

Workspaces live in the cloud, keys live in the Agent, and secrets never touch disk. Every connection is authenticated, every action is recorded, and access can be revoked the moment a device goes missing.

Zero-trust access

ed25519 keys, no shared passwords, no inbound ports.

Secrets vault

Encrypted at rest, injected by reference, never logged.

Immutable audit

Append-only record of every session and change.

Instant revocation

Kill a stolen device’s access in one click.

Connectivity

Zero-trust by construction

The OpusFocus Agent holds your ed25519 key and opens outbound-only tunnels to your workspaces. There are no inbound ports on the laptop, no VPN to misconfigure, and no shared credentials to leak.

  • ed25519 key auth — Per-developer keys; no passwords anywhere in the path
  • Outbound tunnels — Workspaces are never directly exposed to the internet
  • Short-lived sessions — Tunnels expire and re-handshake; no standing access
# import key, open tunnel
$ opusfocus connect atlas-api
→ importing developer.pem · ed25519
→ tunnel eu-west-1 · outbound · 12ms
→ handshake verified · session 30m
✓ secure channel established
No inbound ports No VPN
Secrets

A Vault-lite for every workspace

Store credentials once and inject them into workspaces by reference. Secrets are encrypted at rest, mounted as environment variables at runtime, and never rendered in the UI, logs or snapshots.

  • Reference injection — ${secret:db_url} resolves at boot, never stored in the template
  • Encrypted at rest — AES-256 envelope encryption with per-workspace data keys
  • Redaction everywhere — Values masked in UI, terminal scrollback and audit log
Injected secrets — atlas-api
DATABASE_URL ref:db_primary
REDIS_URL ref:cache
STRIPE_KEY ref:billing
JWT_SECRET ref:auth_signing
•••• values never displayed ••••
Audit

An immutable record of everything

Every SSH login, container attach, package install, snapshot and access decision is written to an append-only log. It's the foundation for compliance evidence, approval workflows and session recording.

  • Append-only — Tamper-evident hash chain; entries can’t be edited or deleted
  • Full coverage — Workspace, container, secret-access and policy events
  • Exportable — Stream to your SIEM or pull SOC 2 evidence on demand
Audit log · live
SSH Login j.okafor → atlas-api 12:04:22
Container Added redis:7.2 → web-console 11:58:09
Snapshot data-pipeline · daily 11:30:00
Access Denied r.vance → infra (policy) 10:47:51
Secret Accessed ref:billing → atlas-api 10:22:14
Access policy

Revoke a stolen laptop in one click

Group developers, scope templates and set who can reach which workspaces. When a device is lost, revoke its keys and every tunnel drops immediately — the work is safe in the cloud, the laptop is now worthless.

  • Role & group scoping — Least-privilege access mapped to teams and templates
  • Instant key revocation — One click invalidates the device; sessions terminate at once
  • Approval workflows — Gate sensitive workspaces behind a second approver
Devices · j.okafor ACTIVE
MacBook Pro 16
ed25519 · last seen 2m ago
ThinkPad X1
ed25519 · revoked
revoked
Compliance

Audited, certified, accountable

Independent attestation across the controls platform teams are asked about in every security review.

SOC 2
Type II
ISO
27001
GDPR
Compliant
HIPAA
Ready
AES-256
secrets at rest
TLS 1.3
in transit
ed25519
key auth
0
shared passwords

Bring your security team
the easy answer.

Whitepaper, SOC 2 report and a live audit-log demo — everything a review needs in one packet.

Explore the platform