Skip to content
Thorfyn

Security and access

Your access, scoped and revocable by you.

1 hlife of the token that touches your repository

  • 2 permissions, only on the repository of the request: run the deploy workflow and read pull requests.
  • 0 of your tokens stored, the database keeps only the installation number, never a token.

We have no SOC 2: this is a one-person company. In exchange, every claim on this page says where you can check it yourself, and only what already exists in the system is stated.

Every row is checked by a test before each deploy. Last: 2026-10-11.

Access register

Everything Thorfyn touches, how long it lasts and how you take it away.

Five accesses, none you cannot end. The ruler shows the life of each on a logarithmic scale; the last column is where you check without asking us.

  • Your GitHub repository

    ScopeThe “Thorfyn Portal” App, only the repository of the request: Actions (write) and Pull requests (read).

    Lasts

    token of 1 h, minted on demand

    How you check or revokeUninstall the App in Settings › Applications. The permission list is shown there, by GitHub, not by us.

  • Invitation to the panel

    ScopeOne email address, single use. There is no self-signup.

    Lasts

    7 days, only a hash is stored

    How you check or revokeIt expires on its own. If it lapses, ask for another.

  • Signing in to the panel

    ScopeAn emailed link, and a passkey offered after the first visit. There is no password.

    Lasts

    link 15 min, session 14 days

    How you check or revokeSigning out ends the session. The passkey is yours, on your device.

  • Publishing to production

    ScopeIn “you approve” mode the publication waits for your click, with a recent passkey check.

    Lasts

    each publication, no duration

    How you check or revokeThe approval is recorded in the panel activity.

  • Admin area

    ScopeThorfyn only. Behind Cloudflare Access; the server checks signature, audience, issuer, expiry and an allow-list of emails.

    Lasts

    the Access session

    How you check or revokeAdmin acts as admin, never as you: the two sessions never mix.

Secrets

Where they live. And where they never do.

The rule is to keep as little as possible, so there is little to leak.

They live here

  • The App private key, the webhook secret and the mail key: Worker secrets, outside the repository.
  • Your client data: every row tied to your tenant.

They never live here

  • A third-party token of yours: the GitHub one is minted for an hour and gone.
  • A password: there is none to leak.
  • A secret in the code or the repository: the .env.example holds names only.

Isolation and record

One client never sees another. The history is not rewritten.

Two rules of the database, not of good will. The drawings show the mechanism, not client data.

Client A

tenant_id = A

orders

activity

Scope by tenantno filter: error

Client B

tenant_id = B

orders

activity

Every read or write of client data goes through a scope; a statement that does not filter by tenant throws. A test proves client A cannot read or write client B, in every store.

Schema, not a real client

Activity only appends

Database triggers refuse to update or delete an activity record. Each record has a protocol number. We say “recorded”, not “signed”.

  1. REQrequest opened
  2. PUBpublished
  3. APRapproved

Personal data. A lead is deleted after 12 months and the hash of its IP address is zeroed after 1 hour. The LGPD and GDPR detail is on the privacy page.

Report

Found a flaw? Tell the person who fixes it.

Email the address below with what you saw, where, and how to repeat it. There is no bounty program. We reply by email. The standard file for machines is at /.well-known/security.txt (RFC 9116).

security.txt
# /.well-known/security.txt
Contact: mailto:hello@thorfyn.comPreferred-Languages: en, pt-BRCanonical: https://thorfyn.com/.well-known/security.txtPolicy: https://thorfyn.com/en/security

What we do not claim

No badge we do not have.

This page describes what exists today. When something changes, it changes in the same commit; what is not yet practice is not on it.

  • A SOC 2 or ISO 27001 certification.
  • A penetration test by a third party.
  • A one-person company: whoever writes the code answers for it.
  • Everything above, which you can check without asking us.

A question before you sign?

Ask by email.