DOCS / SECURITY & OWNERSHIP / SECURITY & TRUST
Security & Trust
How RYHA protects your product, data, and credentials.
Implemented controls include authenticated credential storage with AES-256-GCM, project-scoped memory isolation, audit paths, and approval gates for high-impact actions.
Implemented controls
External credentials stored by the credential gateway use authenticated AES-256-GCM encryption.
Memory access checks scope reads and writes by project and agent context.
Audit paths record supported credential operations.
High-impact workflow actions use explicit approval boundaries where configured.
Boundaries
Security controls reduce risk but do not guarantee that every generated application, deployment, dependency, credential configuration, or third-party integration is vulnerability-free. Project-specific threat modeling, review, testing, and operational configuration remain necessary.
Reporting a concern
To report a security issue, see our security policy at /security-policy or email security@ryha.dev. We aim to acknowledge reports promptly.