Skip to content
Subnomic

Security

Security at Subnomic

Security isn't a feature bolted on afterwards — it's how the product is built. Here's how we protect your workspace, your infrastructure and your data.

No inbound ports

The agent dials out over TLS and refuses to dial anything outside its allowlist. Your hosts don't listen for us — there's nothing to port-scan.

Scoped, expiring credentials

Deploy tokens, storage keys, registry robots and agent accesses are scoped to what they need, can expire, and are shown once.

Encrypted in transit and at rest

TLS in transit. Stored credentials — database passwords, access key secrets, signing keys — are encrypted at rest.

Session recording

Terminal, pod-shell and database sessions are recorded and replayable, attributed to the person who opened them. Database recordings never keep result rows.

Permissions, not privileges

Roles are sets of permissions: reading a database and writing it, watching a session and taking it over, are separate grants.

Passkey sign-in

Passkeys (WebAuthn) for phishing-resistant sign-in, and TOTP two-factor for accounts that still use a password.