SWAGGER::GENESIS

/// technical infrastructure · api · ai_os · registered agents

Account · SSL & Security

4 certificates, all auto-renewing.

Free wildcard SSL, DDoS mitigation, and account-wide two-factor.

4

Certificates

100%

Auto-renew

2FA

Enforced

0

Open findings

DomainTypeStatusExpires
yourbrand.comWildcardValidJul 18, 2027
studio.coSingle hostValidSep 30, 2026
tallgrass.recordsWildcardValidMar 22, 2027
nordlys.studioSingle hostValidDec 04, 2026

DDoS mitigation

Volumetric and application-layer filtering on every plan.

Auto-renewal

Certificates renew 30 days before expiry with rollback.

Two-factor

TOTP and hardware keys enforced across every seat.

2FA coverage · account8 of 8 seats
Hardware key adoption5 of 8 seats
Password rotation < 90d7 of 8 seats
SSO enforcementGoogle Workspace

Seats & roles

MemberRoleMFALast active
alex@yourbrand.comOwnerYubiKey2m ago
jules@yourbrand.comAdminYubiKey1h ago
ops@yourbrand.comDeployerTOTPToday
billing@yourbrand.comRead-onlyTOTP3d ago

Recent security events

  1. 2h ago

    SSL auto-renewed

    yourbrand.com wildcard · valid through Jul 18, 2027

  2. Yesterday

    Sign-in from new device

    Approved from MacBook · San Antonio, TX

  3. 4d ago

    Recovery codes regenerated

    10 new codes issued to owner account

  4. 9d ago

    Vulnerability scan complete

    0 critical · 0 high · 2 informational

// audit.stream

Signed audit trail, always on

Every sign-in, permission change, DNS write, and mailbox creation is captured, signed, and forwarded to your SIEM by the platform. Nothing to wire up — the gateway ships it for you.

Cybersecurity shield with padlock over sky blue circuitry
SOC 2 and ISO 27001 controls enforced at the edge.

DDoS mitigation

Volumetric and application-layer filtering up to 500 Gbps on every plan.

Auto-renewal

Certificates renew 30 days before expiry with rollback if the new cert fails ACME.

Hardware keys

WebAuthn/FIDO2 enforced per role — YubiKey, Titan, Passkeys supported.

Vulnerability scans

Weekly external scans of every site with severity-scored findings.

IP allow-lists

Restrict panel and SSH access to named CIDR ranges per team.

Role-based access

Owner, Admin, Deployer, Billing, Read-only — with per-product overrides.

How are certificates issued?+

Let's Encrypt via ACME by default, ZeroSSL as an automatic fallback. Bring your own paid EV cert if compliance requires it.

Do you support SSO?+

Yes. SAML 2.0 and OIDC with Google Workspace, Okta, Microsoft Entra, JumpCloud, and generic providers. SCIM 2.0 for user provisioning.

What logs are retained?+

Sign-in and admin events for 400 days, DNS writes for 90 days, mail delivery events for 30 days. Longer retention available on Enterprise.

Can I enforce recovery-code print-outs?+

Yes. Admins can require recovery-code confirmation before enabling any privileged role and revoke the codes at will.