SEC

Security boundaries

Explicit authority. Narrow credentials. No imaginary guarantees.

Security starts by naming which component owns each decision. BernOps applies workspace and project authorization, scoped credentials, and bounded workflows; infrastructure operators still own host and workload isolation.

01

Identity follows the workload

Human requests use authenticated project access. Project automation uses scoped keys. Every worker has a revocable credential bound to one workspace, and dispatch cannot move that worker into another workspace.

  • Secrets stored as digests where verification permits
  • Separate worker and project credentials
  • Capability enrollment and matching
02

Discovery has two egress gates

The backend validates target URLs and allowed origins before dispatch. The worker repeats DNS, request, redirect, and subresource checks. Private and local targets are rejected by default.

03

Artifacts require care

Traces, screenshots, logs, and attachments can contain sensitive application data. Private storage and short-lived access URLs reduce exposure, but content must be scrubbed before capture or upload.

04

The boundary we do not claim

BernOps does not provide or verify execution isolation. Configure containers, virtual machines, network policy, and host permissions for your risk model. Concurrency settings are not an isolation mechanism.

EARLY ACCESS

Bring browser operations into focus.

Join the waitlist