Skip to content

Security

hxEASM enforces authentication, RBAC, organization-scoped access control, and server-side authorization for protected APIs.

Audit Log

Significant user-driven mutations are recorded in the append-only Audit Log. Ordinary reads and GET requests are not audited.

Audit Log access is admin-only in this release.

See audit-log.md.

Secret Handling

Audit records must not contain passwords, JWTs, refresh tokens, API keys, OTP codes, TOTP secrets, recovery codes, SMTP passwords, Update Center API keys, provider credentials, or Authorization headers.

Settings audit entries redact secret-like keys before storage.

Exposure Changes

Exposure Changes remain a separate subsystem for attack-surface/security changes. They are not the user-action Audit Log.