Trust Center
Security overview
How an Inlinea tenant is built, where its trust boundaries lie, how data is encrypted, who can administer it, and how we build and ship the software.
Design
Single-tenant by design
- One environment per customerYour server, Control Center, Workspace, ZERA gateway and session engine run in your own tenant on their own persistent disk. Images are shared; environments and data are not.
- Policy decided in one placeThe Inlinea server holds identity, groups, service mappings and policy. The gateway enforces the decision; no component can bypass it.
- Nothing opens inbound at your sitesRouting devices and agents dial out to the control plane and to their peers.
- Least exposureReach is granted per resource by Access Rule. The absence of a rule is the absence of a path.
Encryption
In transit and at rest
| Where | How |
|---|---|
| Platform HTTPS, the Workspace, the Control Center | TLS at the edge, certificates issued and renewed automatically |
| Protected Services and Secure Sessions | TLS terminated by the ZERA gateway with the resource's own certificate, so policy can be enforced on the request |
| Agent path between devices | WireGuard® encrypted tunnels, keyed per device, end to end; relay packets cannot be read by the relay |
| Gateway to private application | The gateway's embedded network client dials the destination over the same encrypted private network |
| Browser attestation | Signed heartbeats and an EdDSA-signed, short-lived token per account; the device key is non-extractable |
| At rest | Encrypted persistent disks per tenant; daily snapshots |
Administration
Who can do what
- Roles and scopeOwner, administrator and auditor roles plus custom roles from a permission catalogue; delegated administration by scope.
- AuditedEvery administrative action in the Audit Log: who, what, when.
- Sign-in protectionAttempt limits and blocked addresses on every sign-in, with named reasons and an unblock action.
- API usersService identities with scoped tokens, listed beside people and governed by the same roles.
How we build
Secure development
- Reviewed changesEvery change is reviewed before it merges; scope is kept to the request.
- Dependency scanningThird-party dependencies are scanned and pinned; runtime images are pinned by digest.
- Immutable releasesA release is complete only when every image is published; tenants resolve tags to digests before deploying.
- Signed agent packagesAgent installers are verified against Inlinea's signing keys before they run.