Security

Security is not a feature.
It's the foundation.

Infrastructure management demands the highest standard of protection. Every layer of DoVisual is designed with security as the default, not an afterthought.


Security Architecture

Six layers of protection.

Credentials at rest
Hashed + encrypted

PIN codes are hashed before storage. JWT secrets use 256-bit keys. Server configuration is stored with restricted file permissions (mode 0600). No plaintext credentials.

Authentication
PIN + JWT

6-digit PIN for initial authentication. JWT tokens issued per device with configurable expiry (default 7 days). No passwords — PIN-based auth is simpler and more secure for mobile.

Transport security
TLS 1.3 + WSS

All API calls over HTTPS with TLS 1.3. Terminal sessions over secure WebSocket (WSS). nginx handles SSL termination with Let's Encrypt certificates.

AI permissions
Human-in-the-loop

Every destructive AI action requires your explicit approval via the mobile app. Read-only operations execute instantly. You control what Claude Code can do.

Device isolation
Per-device tokens

Each connected device receives its own JWT with a unique device ID. Compromised devices can be revoked independently without affecting other sessions.

Access logging
Full audit trail

Every API request is authenticated and logged. Device tracking records last active time. Token revocation is immediate and permanent.


Compliance

Standards and certifications.

SOC 2 Type II
In progress

Security, availability, and confidentiality controls independently audited. Comprehensive controls for infrastructure management platforms.

GDPR
Compliant

Full compliance with EU data protection regulations. Data minimization, right to erasure, and data portability supported.

ISO 27001
Planned

Information security management system certification for infrastructure management platforms.


Responsible Disclosure

Found a vulnerability?

We take security reports seriously. If you've found a vulnerability in our platform, please report it responsibly. We commit to acknowledging reports within 24 hours and providing a resolution timeline within 72 hours.