Security & Trust

Verify us. Don't take our word.

Scoped permissions, an audit trail, and stored secrets that cannot be revealed through the dashboard or API.

A vertical trust stack threaded by one line: a write-only vault door with an inbound arrow and a blocked outbound arrow, an append-only audit ledger of timestamped rows, a least-privilege role matrix, and at the base a database wrapped in a row-level-security shield. write-only audit_log 12:04:31 12:04:32 12:04:40 least privilege rls

The proof stack

Trust you can verify, not just read

Row-level security, least-privilege RBAC, an append-only audit trail, and a write-only vault.

Enforced in the database, not the UI

Every table is gated by row-level security, so the same role limits hold identically on the dashboard, REST, WebSockets and MCP. There is no back-door surface where the checks were forgotten.

Least privilege, for real

25 independently gateable sections, each with separate view and edit switches, composed into custom roles. Give a contractor Devices-view without Scripts-edit — precision instead of admin-or-nothing.

Who did what, when — everywhere

An append-only audit trail records every action on every surface, including direct database access. Tail it live, filter it, diff changes, and share a permalink to the exact event in question.

Secrets that can't be read back

The vault stores keys encrypted and write-only. There's no reveal tool or UI on any surface — no MCP tool, no dashboard reveal, and BusyBro can only list secret names, never their values. A secret goes in once and is only ever used by server-side code, never shown.

AI with guardrails

Agents act only within the caller's role, destructive tools require an explicit confirmation, and every action they take is permanently logged. Autonomy, with a paper trail.

Verify it yourself

Check it before you trust it

Three things you can verify from the outside in an afternoon — no sales call, no NDA.

  1. 01

    Scan the response headers

    Scan an HTML page on busymate.dev with a public header scanner or an HTTP client. The table below describes the marketing site’s response policy. Other services, including the dashboard, have separate configurations; verify the exact URL you use. Report any unexpected result with its URL and response headers.

  2. 02

    Read the audit trail yourself

    Open the audit trail in the dashboard. It tails live, so perform an action — rename a device, add a host to an SSL list — and watch the event appear with who did it, from which surface, and when. Filter to one actor or one device, diff a changed setting against its previous value, and copy the permalink. An AI agent's action produces exactly the same kind of event, because agents write to the same trail.

  3. 03

    Report what you find

    Found a header out of place, a role that sees more than it should, or a way to read a secret back? Email the support address with what you tried and what you saw. Security reports go straight to the engineers who own that surface, and we will tell you when it is fixed.

What a header scan should report

Strict-Transport-Security

A long max-age with subdomains included — the browser keeps using HTTPS even if a link says http.

Content-Security-Policy

A policy that names where scripts and frames may come from, so an injected script has nowhere to load from.

X-Content-Type-Options

The nosniff value — the browser trusts the declared content type instead of guessing one.

X-Frame-Options

Deny — the page cannot be framed by another site, which closes clickjacking.

Referrer-Policy

A strict-origin policy — cross-site navigations never leak the full URL you came from.

Permissions-Policy

Camera, microphone and location switched off — the site never asks for a capability it does not use.

Responsible disclosure goes through the support page — the address there reaches the people who can fix it. Support

Enforcement map

Where each guarantee actually lives

A guarantee is only as strong as the layer that enforces it — this is that layer, for each one.

Roles & permissions

Row-level security in the database. The dashboard, REST, WebSockets and MCP all read the same tables under the same rules, so a role limit cannot be bypassed by switching surface.

Audit trail

An append-only record written by the database itself — including direct database access — that the dashboard tails live and agents read through the same tools.

Secrets vault

Encrypted at rest and write-only from every surface; only server-side code resolves a value, at the moment it is used, and nothing displays it.

Agent actions

The caller's role, a confirmation on every destructive tool, and the same audit trail — enforced by the server the agent talks to, never by the client.

Captured traffic

Decrypted on the device or your own proxy. Synced entries are kept for the platform-wide 10-day window and can be deleted at any time.

FAQ

Questions evaluators ask

Is RBAC enforced in the UI or the database?

In the database — every table is row-level-security gated, so the same role limits hold on the dashboard, REST, WebSockets, and MCP alike.

Can an admin read back a stored secret?

No — there is no reveal tool or UI on any surface: no MCP tool (only a list-names tool exists), no dashboard reveal, and BusyBro can only list secret names. Secrets are stored write-only in an AEAD-encrypted vault and used only by server-side code at the moment of use.

Is there an audit trail for AI-agent actions?

Yes — every action an agent takes, including direct database access, is permanently logged in an append-only, cross-surface audit trail with live tail, filters, diffs and shareable permalinks.

Can I give a contractor limited access?

Yes — 25 independently gateable sections each expose separate view/edit switches, composable into custom roles, e.g. Devices-view without Scripts-edit.

How do I report a vulnerability?

Email the address on the support page with what you tried and what you saw. There is no bug-bounty program today; reports go straight to the engineers who own that surface, and you will hear back when it is fixed.

Where is captured data stored, and for how long?

Decryption happens on the device or your proxy. Entries you sync are stored under your own account for the platform-wide 10-day window, then deleted automatically — and you can delete them earlier at any time.

Point it at production

Roles, audit trail, and vault — trust you can check, not just read.

Ask your mate