Self-hosted operator authentication
Password hashing, bounded lockout, opaque digest-only sessions, TOTP, recovery codes, passkeys and provider-neutral OIDC are implemented boundaries.
Security architecture
Nimbrivo Cloud treats identity, tenant isolation, package integrity, provider access and operational evidence as system boundaries—not marketing badges.
Password hashing, bounded lockout, opaque digest-only sessions, TOTP, recovery codes, passkeys and provider-neutral OIDC are implemented boundaries.
Server actions and service methods reauthorize at the data-owning boundary, including inside transactions for sensitive state changes.
Site and organization ownership are explicit in durable records and validated by services instead of relying on URL shape.
Sensitive provider values use authenticated encryption and write-only management patterns with key-rotation support.
Provider and webhook destinations reject unsafe addressing, credentials and redirects, with DNS validation and bounded response handling.
Immutable audit and event records retain who requested a change, the durable transition and the bounded outcome.
Defense in depth
No single UI check is treated as the security boundary. Authorization, validation, atomic state changes and audit evidence remain in the services that own the data.
Build on a stronger foundation
Security controls remain explicit, testable and independent of the visual interface.