Security and access
Your access, scoped and revocable by you.
1 hlife of the token that touches your repository
- 2 permissions, only on the repository of the request: run the deploy workflow and read pull requests.
- 0 of your tokens stored, the database keeps only the installation number, never a token.
We have no SOC 2: this is a one-person company. In exchange, every claim on this page says where you can check it yourself, and only what already exists in the system is stated.
Every row is checked by a test before each deploy. Last: 2026-10-11.
Access register
Everything Thorfyn touches, how long it lasts and how you take it away.
Five accesses, none you cannot end. The ruler shows the life of each on a logarithmic scale; the last column is where you check without asking us.
Your GitHub repository
ScopeThe “Thorfyn Portal” App, only the repository of the request: Actions (write) and Pull requests (read).
Laststoken of 1 h, minted on demand
How you check or revokeUninstall the App in Settings › Applications. The permission list is shown there, by GitHub, not by us.
Invitation to the panel
ScopeOne email address, single use. There is no self-signup.
Lasts7 days, only a hash is stored
How you check or revokeIt expires on its own. If it lapses, ask for another.
Signing in to the panel
ScopeAn emailed link, and a passkey offered after the first visit. There is no password.
Lastslink 15 min, session 14 days
How you check or revokeSigning out ends the session. The passkey is yours, on your device.
Publishing to production
ScopeIn “you approve” mode the publication waits for your click, with a recent passkey check.
Lastseach publication, no duration
How you check or revokeThe approval is recorded in the panel activity.
Admin area
ScopeThorfyn only. Behind Cloudflare Access; the server checks signature, audience, issuer, expiry and an allow-list of emails.
Laststhe Access session
How you check or revokeAdmin acts as admin, never as you: the two sessions never mix.
Secrets
Where they live. And where they never do.
The rule is to keep as little as possible, so there is little to leak.
They live here
- The App private key, the webhook secret and the mail key: Worker secrets, outside the repository.
- Your client data: every row tied to your tenant.
They never live here
- A third-party token of yours: the GitHub one is minted for an hour and gone.
- A password: there is none to leak.
- A secret in the code or the repository: the .env.example holds names only.
Isolation and record
One client never sees another. The history is not rewritten.
Two rules of the database, not of good will. The drawings show the mechanism, not client data.
Client A
tenant_id = A
orders
activity
Client B
tenant_id = B
orders
activity
Every read or write of client data goes through a scope; a statement that does not filter by tenant throws. A test proves client A cannot read or write client B, in every store.
Schema, not a real client
Activity only appends
Database triggers refuse to update or delete an activity record. Each record has a protocol number. We say “recorded”, not “signed”.
- REQrequest opened
- PUBpublished
- APRapproved
Personal data. A lead is deleted after 12 months and the hash of its IP address is zeroed after 1 hour. The LGPD and GDPR detail is on the privacy page.
Report
Found a flaw? Tell the person who fixes it.
Email the address below with what you saw, where, and how to repeat it. There is no bounty program. We reply by email. The standard file for machines is at /.well-known/security.txt (RFC 9116).
# /.well-known/security.txt Contact: mailto:hello@thorfyn.comPreferred-Languages: en, pt-BRCanonical: https://thorfyn.com/.well-known/security.txtPolicy: https://thorfyn.com/en/security
What we do not claim
No badge we do not have.
This page describes what exists today. When something changes, it changes in the same commit; what is not yet practice is not on it.
- A SOC 2 or ISO 27001 certification.
- A penetration test by a third party.
- A one-person company: whoever writes the code answers for it.
- Everything above, which you can check without asking us.
A question before you sign?
Ask by email.