CC10 Security

Private by design.
Verified in layers.

No connected system is “100% secure.” CC10 reduces risk through separation, least privilege, strong identity, encrypted recovery and repeatable checks—and states clearly where assurance ends.

What protects the system

Strong identity

Individual accounts, passkey-capable authentication, short-lived invitations and role-based application access.

Separated exposure

A replaceable public edge handles TLS and public services. Private workloads are reached through authenticated routes and a restricted private network.

Least privilege

Daily users receive daily apps. Operator and infrastructure tools are separate, audited and not part of ordinary navigation.

Encrypted recovery

Service data and databases are exported into client-side encrypted off-site backups, with restore evidence tracked separately from backup timers.

Reproducible configuration

Reviewed private source files define services, routes, roles and client profiles. Secrets remain outside source control.

Defence in depth

HTTPS, HSTS, restrictive security headers, closed registration, host and mesh filtering, pinned service images and health monitoring reduce single-point failures.

Know what leaves the private space

DataDefault handling
Files, private photos, contacts, calendarPrivate Drive; encrypted backup only.
Passwords, recovery and health/legal dataRestricted; never sent through the AI subscription adapter.
Private research and ordinary project contextLocal processing or the explicitly configured Codex subscription path, according to data class.
Social and Pixelfed postsPublic publishing data; federation means other servers may retain copies.
Telemetry and service healthMinimised and operational; the public status view is redacted.

The controls users must complete

  • Use a unique account, a device-bound passkey and one offline recovery method.
  • Keep every device updated, encrypted and protected by a strong screen lock.

What this does not claim

Security work is continuous: patch review, capacity monitoring, restore drills, access review and incident exercises remain recurring tasks. The private operator runbook records dated evidence and unresolved risks without publishing infrastructure details here.

Security contact

Do not include passwords, tokens, recovery material or private files. Provide the affected public URL, time, observed behaviour and a safe way to reply.

Email the security contact security.txt