Workspace Settings & Security

Configure API credentials, inspect the SSRF sandbox defense engine, and manage audit logs.

Organization API Keys

Programmatically trigger crawls, generate demo plans, and export video renders via REST API.

Production CI/CD Webhookdp_live_9f8a••••••••3b12
Created: 10/3/2026
Staging Pipeline Keydp_live_4a1c••••••••8c99
Created: 9/26/2026

Browser Sandbox & SSRF Defense

Zero-trust execution sandbox protects against host network discovery, DNS rebinding, and prompt injection.

RFC 1918 Private IPv4
Blocked (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16)
Cloud Metadata Filter
Blocked (169.254.169.254, metadata.google.internal)
Loopback & Link-Local
Blocked (127.0.0.0/8, ::1, fe80::/10)
Prompt Injection Isolation
Strict <untrusted_scraped_data> Containers

Authenticated Session Encryption

High-security AES-256-GCM authenticated cipher protects user session tokens and credentials.

Cipher: AES-256-GCM (96-bit IV, 128-bit Auth Tag)
Hardware Acceleration: Active (Node.js OpenSSL)
Verified

Security Audit Logs

Immutable record of workspace actions, demo publications, and export events.

PROJECT_CREATEDPROJECT(proj-sample-1)
10:36 AM
DEMO_PUBLISHEDINTERACTIVE_DEMO(taskflow-overview)
09:36 AM
VIDEO_RENDEREDVIDEO(renders/taskflow-1080p.mp4)
10:06 AM