CC10 Security
Private by design.
Verified in layers.
No connected system is “100% secure.” CC10 reduces risk through separation, least privilege, strong identity, encrypted recovery and repeatable checks—and states clearly where assurance ends.
Security posture
What protects the system
Individual accounts, passkey-capable authentication, short-lived invitations and role-based application access.
A replaceable public edge handles TLS and public services. Private workloads are reached through authenticated routes and a restricted private network.
Daily users receive daily apps. Operator and infrastructure tools are separate, audited and not part of ordinary navigation.
Service data and databases are exported into client-side encrypted off-site backups, with restore evidence tracked separately from backup timers.
Reviewed private source files define services, routes, roles and client profiles. Secrets remain outside source control.
HTTPS, HSTS, restrictive security headers, closed registration, host and mesh filtering, pinned service images and health monitoring reduce single-point failures.
Data boundaries
Know what leaves the private space
| Data | Default handling |
|---|---|
| Files, private photos, contacts, calendar | Private Drive; encrypted backup only. |
| Passwords, recovery and health/legal data | Restricted; never sent through the AI subscription adapter. |
| Private research and ordinary project context | Local processing or the explicitly configured Codex subscription path, according to data class. |
| Social and Pixelfed posts | Public publishing data; federation means other servers may retain copies. |
| Telemetry and service health | Minimised and operational; the public status view is redacted. |
Your part
The controls users must complete
- Use a unique account, a device-bound passkey and one offline recovery method.
- Keep every device updated, encrypted and protected by a strong screen lock.
Assurance boundary
What this does not claim
Security work is continuous: patch review, capacity monitoring, restore drills, access review and incident exercises remain recurring tasks. The private operator runbook records dated evidence and unresolved risks without publishing infrastructure details here.
Report a concern
Security contact
Do not include passwords, tokens, recovery material or private files. Provide the affected public URL, time, observed behaviour and a safe way to reply.