Private beta · Pilot access only. Live polling is not enabled yet. Paid checkout is not enabled.

Security and safe outbound requests

All sources and destinations must use HTTPS with verified TLS to public DNS names. IP literals, credentials in URLs, fragments, unusual ports, local/private/reserved ranges, mixed public/private DNS answers and the service’s own control-plane hosts are rejected. Every request resolves and validates all A/AAAA answers, then pins the connection to an approved address with the original TLS hostname. Redirects and inherited proxies are disabled. A separate restricted worker executes outbound requests; production refuses development localhost exceptions.

Credentials are write-only and bound to an exact origin. Envelope encryption protects credentials, source URLs, selected baselines, retained event bodies and temporary worker requests. Deployment secrets hold versioned wrapping keys. API keys are random and stored as hashes. Logs omit credential values, URL query values and selected payloads.

Workspace scoping, role checks and composite database references protect tenant boundaries. Keys may be project scoped, revoked and expired. Browser mutations require CSRF protection. Source responses and MCP results are untrusted data, never instructions.

Report vulnerabilities privately to team@rerunlab.com. Do not test against other tenants or cause denial of service. See /security for operational disclosures. No certification or independent audit is claimed.