Security at DriftSeal
Our trust boundary starts with the fact that the component may be hostile.
No component execution
We do not run package installers, import scanned modules, invoke downloaded executables or call target MCP tools. Artifact and tool hashes describe observed content. They do not certify publisher identity.
Private by default
Reports require the submitting visitor session or workspace access. Owner-approved public status pages reveal only monitoring status and recency. Webhook destinations use encrypted signing secrets and public-network-only delivery.
Operational controls
Separate web and worker processes, dedicated PostgreSQL storage, non-root containers, read-only application filesystems, bounded temporary storage, no Docker socket mounts and restricted resources are part of the deployment design. Verification status is recorded in the release report.
Report an issue
Send a minimal reproduction to support@maib.io. Do not include live credentials or unrelated user data. Follow the responsible disclosure page. Use Security disclosure in the subject.
Establish your baseline.
Inspect a public component or use the local CLI for private source.
Scan a component — free ↗