Security
Secure by construction. Boring on purpose.
Letting an agent push code is a big deal. So the rules live in the database, where a bug in one endpoint can't quietly skip them.
What Aictiq guarantees
- Tenant isolation fails closed.No organization means no rows, never all rows. Postgres row-level security as the second guard.
- One live run per ticket.A database constraint, not a convention.
- Tokens die with the run.Each run gets its own agent token, revoked on success, failure, cancel, timeout or runner loss, and it expires on its own anyway.
- Runner secrets can only talk to the runner API.Not projects, not users, not MCP.
- Agents can't escalate.They can't log in, can't create credentials, and are labeled as agents everywhere.
- Credentials are stored once, as hashes.Replaying a spent refresh token revokes the whole family.
- History is append-only.Audit log and item history reject UPDATE and DELETE by trigger.
- 404, not 403.A refusal never confirms that a project exists.
- Prompt injection labeled.Content from tickets, comments and wiki reaches agents inside explicit "user-controlled content" boundaries.
- No surprises outbound.Webhooks and link previews only reach public addresses, checked at connect time, no redirects followed.
- Bot protection.Cloudflare Turnstile and email confirmation on public instances.
- Telemetry off by default.When an operator turns it on: version and aggregate counts, no IDs, no content.
What you're responsible for
The runner is not a sandbox.
The agent runs as the OS user you choose, with that user's files and credentials. Use a dedicated machine or VM and an unprivileged user. That's the deal, and it's a fair one: your code never has to leave your hardware.
- Keep secrets out of tickets and playbooks.
- Review agent PRs before merging. Aictiq never merges or deploys for you.
- CodeQL
- OpenSSF Scorecard
- AGPL source
- Private vulnerability reporting via GitHub
Found something? Report it privately through GitHub security advisories.
Read the model. Then run it on your own box.
Open source under AGPL-3.0, so you can read every line of it.