Security
Updated 2026-09-18
UseJunction protects hosted data with TLS in transit, hashed device tokens, encrypted integration secrets, role-based access, production environment guards, and audit logs for sensitive actions. EU workspaces stay on the EU deployment.
Measures
Transport: HTTPS in production; loopback HTTP only for local development.
Secrets: device tokens and enrollment tokens stored as hashes; integration credentials encrypted at rest with INTEGRATION_ENCRYPTION_KEY; production rejects known default secrets.
Access control: organization roles (owner, admin, manager, user). Privacy export and erasure require owner or admin. Raw work-trace viewing is audited.
Isolation: each workspace is scoped by orgId. US and EU hosted regions use separate applications and databases.
Application security: CSRF-style browser mutation guards, rate limiting, CSP, and no indexing of private app routes.
Operations: cron jobs require CRON_SECRET; agent release promotion uses a dedicated operations token.
Reporting
Report security issues to hello@usejunction.dev. We do not run a public bug bounty at this time.
FAQ
- Is data encrypted at rest?
- Integration secrets are encrypted in the application. Database-at-rest encryption is provided by the managed Postgres host; confirm the EU or US provider configuration for your region.
