RYHA documentation portal. Find the quickstart guide, step-by-step tutorials, in-depth feature guides, draft REST API source contracts, and the product changelog for the RYHA software-delivery platform.

RYHARYHADocumentation
Dashboard
DOCS / SECURITY & OWNERSHIP / SECURITY & TRUST

Security & Trust

How RYHA protects your product, data, and credentials.

Implemented controls include authenticated credential storage with AES-256-GCM, project-scoped memory isolation, audit paths, and approval gates for high-impact actions.

Implemented controls

External credentials stored by the credential gateway use authenticated AES-256-GCM encryption.
Memory access checks scope reads and writes by project and agent context.
Audit paths record supported credential operations.
High-impact workflow actions use explicit approval boundaries where configured.

Boundaries

Security controls reduce risk but do not guarantee that every generated application, deployment, dependency, credential configuration, or third-party integration is vulnerability-free. Project-specific threat modeling, review, testing, and operational configuration remain necessary.

Reporting a concern

To report a security issue, see our security policy at /security-policy or email security@ryha.dev. We aim to acknowledge reports promptly.
← PREVIOUSBounded Project CapacityNEXT →Code, Data & Ownership