Skip to content

Security boundaries

  • Bucket access is restricted via least-privilege IAM
  • Scanner tokens are tenant-scoped
  • Optional custom domain reduces allowlisting complexity
  • Secrets stay inside Kubernetes Secrets and customer-controlled storage