Public beta · Explore the first Clouddory APIPlatform status ↗
CLOUDDORY DOCUMENTATION

Security & trust boundaries

The platform is in public beta. Do not use it for sensitive production workloads.

Customer access

Passwords are hashed with Argon2id. Session cookies are HttpOnly and SameSite=Lax; Secure is required when served over HTTPS. State-changing customer requests validate their Origin. API-key secrets are stored only as SHA-256 hashes.

Organization isolation

Customer actions check organization membership. API keys access only their own organization’s activated services. The first release supports one owner-created organization per account; member invitations are not yet available.

AI execution

Workers execute through Codex CLI in isolated Linux namespaces and restricted sandboxes. They receive no production, billing, owner, database or Cloudflare credentials. Third-party repository execution is gated pending further hardening.

Preview limitations

Email verification, password recovery delivery, off-server backup retention, external uptime monitoring and live Stripe reconciliation must be configured and verified before paid general availability. No security certification, availability SLA, or compliance claim is made.

Public beta: free service available. Paid billing and account recovery are not yet enabled.