Security

How WHYBLE. is secured

WHYBLE. acts on real systems, so security is structural: identity first, actions gated, everything recorded.

Identity

Sign-in runs through our identity provider (OpenID Connect) with short-lived tokens. Access is scoped by tenant — users and services only see the tenants they belong to.

Actions are gated

Watching and remembering are always allowed. Acting is not: publishing, messaging and mutating real systems sit behind approval policies, and sensitive actions stay on a human claim until someone approves them.

Auditability

Signals, decisions and actions are recorded as events with provenance. What the system saw, what it decided and what it did can be replayed — that is how the reports stay honest.

Data handling

Tenant data stays inside its tenant. Credentials live in a dedicated vault, never in code or mission output. The market board on this site republishes public statistics only, with source attribution.

Report a problem

Found a vulnerability or something that looks wrong? Mail hello@hybridin.io and we will look at it. Please do not include other people's data or credentials in the report.