Private beta · Request a scoped Agent Firewall evaluation

RaksHex Security

Security architecture

Private beta · aligned with the Trust Center. Reviewers should start at /trust and email security@rakshex.in.

What this page is

RaksHex is an Agent Firewall: runtime authorization for autonomous AI actions. This page describes controls that exist in the current product and in docs/SECURITY.md. It is not a certification, an audit report, or a data-residency catalog. Where a control is not yet in the private-beta cut, it is omitted rather than described as shipped.

1. Threat model

We protect against the following categories when traffic is evaluated through the Agent Firewall and related governance paths:

Unauthorised agent actions

Semantic actions are authorised against delegated authority before they run. A child authority cannot exceed its parent. A DENY is enforced at credential mediation, not only as an advisory log line.

Prompt injection and insecure output handling

Gateway and scanning paths inspect prompts and tool calls for injection and unsafe output patterns. Coverage depends on deployment configuration.

Credential and secret exposure

Workspace credentials are encrypted before storage. List APIs return masked metadata and fingerprints. Discovery is designed to send masked metadata rather than secret values.

Excessive agency

Kill switches, budgets, and tool allowlists can stop further calls when a policy trips. Response time depends on deployment topology.

2. Encryption and authentication

  • Passwords: hashed with Argon2id. Legacy PBKDF2-SHA512 hashes are verified only for migration and upgraded on next successful login.
  • Sessions: server-side sessions with HTTP-only cookies and CSRF protections on browser flows. OAuth uses PKCE.
  • Multi-factor: TOTP-based 2FA is available for accounts that enable it.
  • Workspace access: membership-scoped RBAC. API keys are hashed at rest. Cross-tenant access is denied by authorization helpers.
  • Credentials: encrypted in a workspace-scoped vault. Secrets are not returned on list endpoints and do not leave the server on brokered calls.

3. Runtime enforcement

  • Action Ledger: hash-chained, tamper-evident record of authorization decisions.
  • Credential mediation: a DENY prevents the secret from being used. Shadow mode cannot launder a denied action into a brokered call.
  • Kill switch: workspace, project, and agent kill switches on the gateway path. Fail-open versus fail-closed is configurable; emergency bypass is audited.
  • Logging: structured logs redact passwords, tokens, API keys, and cookies. Raw prompts are not retained by default in hosted audit records.

4. Compliance

RaksHex maps product controls to common frameworks (including OWASP, NIST AI RMF, ISO, SOC 2, GDPR, DPDP, and the EU AI Act) and can export that evidence. We do not claim a certification or independent audit until that assessment is complete and published. Dashboard scores and PDFs, where present, are mapping artifacts for your own audit workflow — not an attestation that RaksHex is SOC 2, PCI DSS, OWASP, or ISO certified.

Data-processing terms, subprocessors, and transfer language live in the Legal Center. Residency, private relay, and self-hosted deployment are agreed on an enterprise Order Form when they apply; they are not marketed here as a standard product option.

5. Incident contact

Report suspected vulnerabilities, privacy requests, legal notices, or security incidents to security@rakshex.in. Do not send provider keys, passwords, or sensitive evidence by email.

Verifiable commitments are on the Trust Center. This page will not list a badge, audit-in-progress status, or residency region until that evidence is published.