No-Code SaaS Automation Platform  ·  View 19 of 21  ·  Assurance

Security Zones

Six zones by decreasing exposure, and every crossing labelled. The custody zone is a separate account on purpose.

Editable source SVG draw.io All views
Internet — untrusted Provider push callers Author browser Provider APIs Perimeter WAF and ALB Signed push endpoint Author API SSO Application — platform VPC Admission Step runners Connector sandbox no credentials Controlled egress Quota governor NAT, static range Custody — separate account Credential custody Key service Data Trigger event log Step ledger signature only commit sandboxed effect token allowlist Security — Trust Zones and Crossings External / third party Person or role Interface / broker Application we own Security / platform Data store synchronous Author-supplied URLs in generic HTTP steps are resolved and re-checked after redirect, so the platform cannot be used as a proxy into these zones. v 1.0 · owner Integration Platform Architecture · date 2026-10

Decisions

  • The connector sandbox sits in the application zone with no credential in scope beyond the single connection it serves, a CPU and wall-clock ceiling, no filesystem persistence, and egress only to the hosts its manifest declares.
  • Custody is a zone of its own, reached only by token exchange at the egress boundary. The runner never holds a credential it could reuse, and the refresh token never leaves the zone.
  • Provider responses crossing inward are untrusted input: schema-validated, size-bounded, and unable to influence an automation's control flow.

Threats designed against

  • Server-side request forgery through a generic HTTP step: author-supplied URLs are resolved and checked against internal, link-local and metadata ranges, and re-checked after every redirect.
  • Unauthenticated push: a delivery without a valid per-connection signature is rejected before it reaches the event log.
  • Credential exfiltration via logs: plaintext never appears in logs, run history, error messages or the ledger, and that is a zero-tolerance assertion.

Risks

  • Catch-hooks and platform-hosted mail addresses are public endpoints by design, and are the most exposed surface in the set.
  • Partner connector code in the sandbox is the largest residual risk, and Core Architecture Question 7 is whether to accept it at all.