# Security and access — Thorfyn

Canonical URL: https://thorfyn.com/en/security

> How we ask for, hold and return access to your code: GitHub tokens that last 1 hour, no passwords, isolation per client, and how to report a flaw.

Your access, scoped and revocable by you.

We have no SOC 2: this is a one-person company. In exchange, every claim on this page says where you can check it yourself, and only what already exists in the system is stated.

- 1 h: life of the token that touches your repository
- 2 permissions: only on the repository of the request: run the deploy workflow and read pull requests.
- 0 of your tokens stored: the database keeps only the installation number, never a token.
- Every row is checked by a test before each deploy. Last: 2026-10-11.

## Everything Thorfyn touches, how long it lasts and how you take it away.

Five accesses, none you cannot end. The ruler shows the life of each on a logarithmic scale; the last column is where you check without asking us.

- Your GitHub repository. Scope: The “Thorfyn Portal” App, only the repository of the request: Actions (write) and Pull requests (read). Lasts: token of 1 h, minted on demand. How you check or revoke: Uninstall the App in Settings › Applications. The permission list is shown there, by GitHub, not by us.
- Invitation to the panel. Scope: One email address, single use. There is no self-signup. Lasts: 7 days, only a hash is stored. How you check or revoke: It expires on its own. If it lapses, ask for another.
- Signing in to the panel. Scope: An emailed link, and a passkey offered after the first visit. There is no password. Lasts: link 15 min, session 14 days. How you check or revoke: Signing out ends the session. The passkey is yours, on your device.
- Publishing to production. Scope: In “you approve” mode the publication waits for your click, with a recent passkey check. Lasts: each publication, no duration. How you check or revoke: The approval is recorded in the panel activity.
- Admin area. Scope: Thorfyn only. Behind Cloudflare Access; the server checks signature, audience, issuer, expiry and an allow-list of emails. Lasts: the Access session. How you check or revoke: Admin acts as admin, never as you: the two sessions never mix.

## Where they live. And where they never do.

The rule is to keep as little as possible, so there is little to leak.

### They live here

- The App private key, the webhook secret and the mail key: Worker secrets, outside the repository.
- Your client data: every row tied to your tenant.

### They never live here

- A third-party token of yours: the GitHub one is minted for an hour and gone.
- A password: there is none to leak.
- A secret in the code or the repository: the .env.example holds names only.

## One client never sees another. The history is not rewritten.

Two rules of the database, not of good will. The drawings show the mechanism, not client data.

- **Scope by tenant** — Every read or write of client data goes through a scope; a statement that does not filter by tenant throws. A test proves client A cannot read or write client B, in every store. (Schema, not a real client.)
- **Activity only appends** — Database triggers refuse to update or delete an activity record. Each record has a protocol number. We say “recorded”, not “signed”.

- REQ: request opened
- PUB: published
- APR: approved

Personal data: A lead is deleted after 12 months and the hash of its IP address is zeroed after 1 hour. The LGPD and GDPR detail is on the privacy page (https://thorfyn.com/en/privacy).

## Found a flaw? Tell the person who fixes it.

Email the address below with what you saw, where, and how to repeat it. There is no bounty program. We reply by email. The standard file for machines is at /.well-known/security.txt (RFC 9116).

- security.txt: https://thorfyn.com/.well-known/security.txt
- Questions and requests: hello@thorfyn.com

## No badge we do not have.

This page describes what exists today. When something changes, it changes in the same commit; what is not yet practice is not on it.

- A SOC 2 or ISO 27001 certification.
- A penetration test by a third party.
- A one-person company: whoever writes the code answers for it.
- Everything above, which you can check without asking us.

- Back to the home page: https://thorfyn.com/en
