Verify us.
Scoped permissions, an audit trail, and stored secrets that cannot be revealed through the dashboard or API.
Trust you can verify,
Row-level security, least-privilege RBAC, an append-only audit trail, and a write-only vault.
Enforced in the database, not the UI
Every table is gated by row-level security, so the same role limits hold identically on the dashboard, REST, WebSockets and MCP. There is no back-door surface where the checks were forgotten.
Least privilege, for real
25 independently gateable sections, each with separate view and edit switches, composed into custom roles. Give a contractor Devices-view without Scripts-edit — precision instead of admin-or-nothing.
Who did what, when — everywhere
An append-only audit trail records every action on every surface, including direct database access. Tail it live, filter it, diff changes, and share a permalink to the exact event in question.
Secrets that can't be read back
The vault stores keys encrypted and write-only. There's no reveal tool or UI on any surface — no MCP tool, no dashboard reveal, and BusyBro can only list secret names, never their values. A secret goes in once and is only ever used by server-side code, never shown.
AI with guardrails
Agents act only within the caller's role, destructive tools require an explicit confirmation, and every action they take is permanently logged. Autonomy, with a paper trail.
Check it
Three things you can verify from the outside in an afternoon — no sales call, no NDA.
- 01
Scan the response headers
Scan an HTML page on busymate.dev with a public header scanner or an HTTP client. The table below describes the marketing site’s response policy. Other services, including the dashboard, have separate configurations; verify the exact URL you use. Report any unexpected result with its URL and response headers.
- 02
Read the audit trail yourself
Open the audit trail in the dashboard. It tails live, so perform an action — rename a device, add a host to an SSL list — and watch the event appear with who did it, from which surface, and when. Filter to one actor or one device, diff a changed setting against its previous value, and copy the permalink. An AI agent's action produces exactly the same kind of event, because agents write to the same trail.
- 03
Report what you find
Found a header out of place, a role that sees more than it should, or a way to read a secret back? Email the support address with what you tried and what you saw. Security reports go straight to the engineers who own that surface, and we will tell you when it is fixed.
Strict-Transport-SecurityA long max-age with subdomains included — the browser keeps using HTTPS even if a link says http.
Content-Security-PolicyA policy that names where scripts and frames may come from, so an injected script has nowhere to load from.
X-Content-Type-OptionsThe nosniff value — the browser trusts the declared content type instead of guessing one.
X-Frame-OptionsDeny — the page cannot be framed by another site, which closes clickjacking.
Referrer-PolicyA strict-origin policy — cross-site navigations never leak the full URL you came from.
Permissions-PolicyCamera, microphone and location switched off — the site never asks for a capability it does not use.
Responsible disclosure goes through the support page — the address there reaches the people who can fix it. Support
Where each guarantee
A guarantee is only as strong as the layer that enforces it — this is that layer, for each one.
Roles & permissionsRow-level security in the database. The dashboard, REST, WebSockets and MCP all read the same tables under the same rules, so a role limit cannot be bypassed by switching surface.
Audit trailAn append-only record written by the database itself — including direct database access — that the dashboard tails live and agents read through the same tools.
Secrets vaultEncrypted at rest and write-only from every surface; only server-side code resolves a value, at the moment it is used, and nothing displays it.
Agent actionsThe caller's role, a confirmation on every destructive tool, and the same audit trail — enforced by the server the agent talks to, never by the client.
Captured trafficDecrypted on the device or your own proxy. Synced entries are kept for the platform-wide 10-day window and can be deleted at any time.
Questions evaluators
Is RBAC enforced in the UI or the database?
In the database — every table is row-level-security gated, so the same role limits hold on the dashboard, REST, WebSockets, and MCP alike.
Can an admin read back a stored secret?
No — there is no reveal tool or UI on any surface: no MCP tool (only a list-names tool exists), no dashboard reveal, and BusyBro can only list secret names. Secrets are stored write-only in an AEAD-encrypted vault and used only by server-side code at the moment of use.
Is there an audit trail for AI-agent actions?
Yes — every action an agent takes, including direct database access, is permanently logged in an append-only, cross-surface audit trail with live tail, filters, diffs and shareable permalinks.
Can I give a contractor limited access?
Yes — 25 independently gateable sections each expose separate view/edit switches, composable into custom roles, e.g. Devices-view without Scripts-edit.
How do I report a vulnerability?
Email the address on the support page with what you tried and what you saw. There is no bug-bounty program today; reports go straight to the engineers who own that surface, and you will hear back when it is fixed.
Where is captured data stored, and for how long?
Decryption happens on the device or your proxy. Entries you sync are stored under your own account for the platform-wide 10-day window, then deleted automatically — and you can delete them earlier at any time.
Point it at
Roles, audit trail, and vault — trust you can check, not just read.