Trust
Security
The current technical and product boundaries used to keep Huske focused on scoped project memory instead of production control.
Beta notice / Effective July 18, 2026
Authentication and workspace scoping
Clerk provides authentication. Server-side workspace resolution scopes database reads, writes, actions, API routes, captures, exports, restores, provider operations, and project activity to the authenticated workspace instead of trusting client-supplied workspace identifiers.
Metadata-first integrations
GitHub, GitLab.com, and Bitbucket Cloud setup flows use repository metadata rather than source files. Vercel, Netlify, Cloudflare, and Railway provide deployment and resource metadata. Synced provider facts remain separate from user-approved Huske memory and do not overwrite non-blank user edits.
Credential handling
Connected provider tokens are encrypted for server-side use. Disconnect removes the credential without silently deleting facts. Purge is a separate confirmed action that removes provider facts, sync history, and provider activity history while retaining user-approved workspace memory.
Secret-aware context analysis
User-initiated context paste or upload is size-limited, URL-filtered, and scanned for likely API keys, tokens, database URLs, environment secrets, and private keys. Raw context can remain in IndexedDB on the user's device for seven days of inactivity, but never enters database-backed drafts. Findings are redacted before optional OpenAI analysis; only normalized, redacted analysis and reviewed derived memory are eligible for server storage.
Review before mutation
Captures, Project Agent suggestions, and cleanup recommendations are staged in Decisions for approval, adjustment, dismissal, or keep-as-is handling. Archive preflight exposes billing, shared-service, provider-resource, domain, and memory blockers before changing the Huske record.
Scoped Project Agent grants
Project Agent grants expire and are limited to one saved context pack plus explicit read and suggestion-stage scopes. Tokens are shown once and can be rotated or revoked. They cannot access export, provider mutations, billing, DNS, secrets, production controls, or workspace-wide activity history.
Error and abuse protection
Sensitive API routes use trusted-origin checks, request-size limits, rate limits, and fail-closed authentication. Sentry is optional and uses strict event scrubbing when configured. Cloudflare Turnstile is optional for anti-abuse challenges. Vercel Analytics and Speed Insights provide product and performance telemetry.
Storage and recovery
Workspace records use Neon/PostgreSQL. Participating forms save immediately to versioned IndexedDB and can sync an allow-listed workspace draft to the server. Both recovery layers expire after seven days of inactivity; IndexedDB quota or privacy-mode failures are reported in the form. Authenticated pages are not cached for offline reload. Private project media uses private Vercel Blob storage when configured. Workspace deletion revokes provider credentials and Project Agent grants, locks access, and provides a 30-day recovery window before records become eligible for scheduled permanent purge.
Report a concern
Email hello@huske.io with a concise description of a suspected security or privacy issue. This page describes current beta safeguards; it is not a compliance certification or penetration-test claim.
Report a security concern