Security model
People: passkeys
Section titled “People: passkeys”- Sign-in is by passkey only. One person requests an invite, a second approves, an administrator issues a one-time code (72 hours, shown once). Registration needs a key stored on the device and user verification.
- Sign-in returns a random 256-bit session token; the server keeps only its SHA-256. A session lasts at most 12 hours and ends after 30 idle minutes. The console keeps the token in memory only; the API sets no cookies and requires an allowed
Originfrom browsers. - Step-up (a passkey assertion within the last five minutes): approvals, invites, identity changes, deletion requests, disabling people, full exports, roll requests and key loss declarations.
- A person who loses every passkey is recovered on the same account: an administrator requests it, someone outside that person’s chain approves, a 24-hour code is issued, and redeeming it removes the old passkeys and sessions.
Machines: mutual TLS
Section titled “Machines: mutual TLS”- Mutual TLS over TLS 1.3. Certificates come from the cell’s own client CA, last seven days and renew with a CSR over mutual TLS. The key is generated on the machine.
- Bootstrap: a one-time code (24 hours, shown once) is swapped with a CSR for the first certificate, only while the identity holds none. A machine that loses its key gets a new identity.
- Every identity has scopes and an optional IP allow list. Revocation applies on the next request. Machines never hold human scopes.
Two-person rule
Section titled “Two-person rule”These actions wait for a second person’s decision: a new machine identity, a new invite, a passkey recovery, a full or large export, a large or batch deletion, a key loss declaration; on the platform, activating an organisation and lifting a suspension.
The decider cannot be the requester, anyone who controls the requester, anyone the requester controls, or anyone who shares a controller with the requester. Every approval runs once. Details: Approvals and the two-person rule.
Trust boundary
Section titled “Trust boundary”- Residency: the data plane and the key hardware run in the Türkiye cell; the console stores no data.
- Isolation: every cell has its own endpoint, database, private swarm, HSM partition, keys, signing key, client CA and console.
- Limits: 50 requests per second per identity (burst 100), and every route has a time budget. Details: API basics.