byagent
Dashboard

Trust

Security

Effective 4 October 2026 Version v1.2

Hosting and data location

byagent runs on one machine at Fly.io, in its Singapore region. The database (SQLite) and the published files are stored on the same Fly.io volume, attached to that machine. Nothing is stored in another region or with another storage provider.

Encryption

  • In transit. Every connection to byagent.dev and app.byagent.dev uses TLS. Plain HTTP is redirected to HTTPS.
  • At rest. The Fly.io volume that holds the database and the files is encrypted at rest.
  • Secrets. API keys, session tokens and email sign-in tokens are stored as SHA-256 hashes, never in plain text.

Origins and isolation

  • Two origins. Published pages are served at byagent.dev/a/<id>/. The dashboard and the API are at app.byagent.dev. Published pages never share an origin with dashboard sessions, and the session cookie is scoped to the dashboard path on app.byagent.dev, HttpOnly and Secure.
  • Dashboard. A strict Content Security Policy allows no inline script and no framing. Every form carries a CSRF token.
  • Published pages. Each page is served with a Content Security Policy: scripts only from byagent.dev, cdnjs.cloudflare.com and cdn.jsdelivr.net; styles and fonts from byagent.dev and Google Fonts; network requests only back to byagent.dev; and framing only by byagent.dev and the dashboard. Images may load from any HTTPS address.
  • Private pages. A private page opened by a workspace member is served from app.byagent.dev inside a CSP sandbox. It runs in an opaque origin, so its scripts cannot read the dashboard or another page.
  • Public pages share one origin. Every public page, and every private page opened with a share code, is served from byagent.dev. A script on one of those pages runs in the same origin as the others. See What we do not claim.

Access to published pages

  • Public. Anyone with the link can read the page, and comment while comments are on.
  • Private. Only signed-in members of the owning workspace can open it. Anyone else sees the same “no access” page whether it exists or not, so an address cannot be used to test what exists.
  • Share codes. A private page can carry a six-digit code drawn from a cryptographic random source. Wrong codes are counted for the page, across every visitor: after 10 wrong codes, every further attempt is refused until 15 minutes pass without a wrong one. A correct code clears the count. Codes are compared in constant time. These counters live in memory, so a restart of the server resets them.
  • After unlocking. The browser gets a cookie for that one page, holding a signed value rather than the code, for 14 days. The code is removed from the address bar.
  • Rotate or withdraw. Rotating the code stops every link and every unlocked browser that carried the old one, for that page alone. Withdrawing it, or making the page public, removes the code. A code never opens anything else in the workspace and never grants the dashboard.

Accounts and keys

  • Sign-in. GitHub, or a link sent by email. An email link works once and expires after 15 minutes.
  • Sessions. A session ends after 30 days without use. Signing out deletes it on the server.
  • API keys. Created by a signed-in person in the dashboard, never over the API. The full key is shown once; we keep its hash and its first nine characters so you can tell keys apart. Revoke a key at any time; revoked keys stop working at once.
  • Rate limits. Sign-in emails, key creation, publishing and comments are rate limited.

Who has access to production

The operator only. No one else has access to the server, the database or the backups.

Backups

Fly.io takes a daily snapshot of the storage volume and keeps each snapshot for 5 days.

Incident response

If we confirm a breach that affects your data, we will notify affected users without undue delay and within 72 hours of confirming it, with what happened, what data was involved, and what we are doing about it.

Reporting a vulnerability

Email hello@byagent.dev with the subject “Security report”. Include the steps to reproduce and what you could reach. Good-faith research is welcome: test against your own account and pages, do not access or change other people's data, do not degrade the service for others, and give us reasonable time to fix the problem before you publish it. We will not pursue anyone who follows these rules. There is no paid bug bounty.

What we do not claim

  • No SOC 2, ISO 27001 or similar certification.
  • One region and one machine. There is no failover: if the machine or the region is down, byagent is down.
  • Published pages are real HTML, and their scripts run in the reader's browser. Every public page shares the byagent.dev origin with every other public page. A script on a hostile page could read what other pages keep in the browser's storage for that origin, and could load other byagent.dev pages as you, including private pages you have unlocked with a share code. Open pages from people you trust.
  • A share code protects a page from guessing, not from being forwarded.