Security

Secure by construction. Boring on purpose.

Letting an agent push code is a big deal. So the rules live in the database, where a bug in one endpoint can't quietly skip them.

What Aictiq guarantees

  • Tenant isolation fails closed.No organization means no rows, never all rows. Postgres row-level security as the second guard.
  • One live run per ticket.A database constraint, not a convention.
  • Tokens die with the run.Each run gets its own agent token, revoked on success, failure, cancel, timeout or runner loss, and it expires on its own anyway.
  • Runner secrets can only talk to the runner API.Not projects, not users, not MCP.
  • Agents can't escalate.They can't log in, can't create credentials, and are labeled as agents everywhere.
  • Credentials are stored once, as hashes.Replaying a spent refresh token revokes the whole family.
  • History is append-only.Audit log and item history reject UPDATE and DELETE by trigger.
  • 404, not 403.A refusal never confirms that a project exists.
  • Prompt injection labeled.Content from tickets, comments and wiki reaches agents inside explicit "user-controlled content" boundaries.
  • No surprises outbound.Webhooks and link previews only reach public addresses, checked at connect time, no redirects followed.
  • Bot protection.Cloudflare Turnstile and email confirmation on public instances.
  • Telemetry off by default.When an operator turns it on: version and aggregate counts, no IDs, no content.

What you're responsible for

The runner is not a sandbox.

The agent runs as the OS user you choose, with that user's files and credentials. Use a dedicated machine or VM and an unprivileged user. That's the deal, and it's a fair one: your code never has to leave your hardware.

  • Keep secrets out of tickets and playbooks.
  • Review agent PRs before merging. Aictiq never merges or deploys for you.
  • CodeQL
  • OpenSSF Scorecard
  • AGPL source
  • Private vulnerability reporting via GitHub

Found something? Report it privately through GitHub security advisories.

Read the model. Then run it on your own box.

Open source under AGPL-3.0, so you can read every line of it.