Trust

Security

The current technical and product boundaries used to keep Huske focused on scoped project memory instead of production control.

Beta notice / Effective July 18, 2026

Authentication and workspace scoping

Clerk provides authentication. Server-side workspace resolution scopes database reads, writes, actions, API routes, captures, exports, restores, provider operations, and project activity to the authenticated workspace instead of trusting client-supplied workspace identifiers.

Metadata-first integrations

GitHub, GitLab.com, and Bitbucket Cloud setup flows use repository metadata rather than source files. Vercel, Netlify, Cloudflare, and Railway provide deployment and resource metadata. Synced provider facts remain separate from user-approved Huske memory and do not overwrite non-blank user edits.

Credential handling

Connected provider tokens are encrypted for server-side use. Disconnect removes the credential without silently deleting facts. Purge is a separate confirmed action that removes provider facts, sync history, and provider activity history while retaining user-approved workspace memory.

Secret-aware context analysis

User-initiated context paste or upload is size-limited, URL-filtered, and scanned for likely API keys, tokens, database URLs, environment secrets, and private keys. Raw context can remain in IndexedDB on the user's device for seven days of inactivity, but never enters database-backed drafts. Findings are redacted before optional OpenAI analysis; only normalized, redacted analysis and reviewed derived memory are eligible for server storage.

Review before mutation

Captures, Project Agent suggestions, and cleanup recommendations are staged in Decisions for approval, adjustment, dismissal, or keep-as-is handling. Archive preflight exposes billing, shared-service, provider-resource, domain, and memory blockers before changing the Huske record.

Scoped Project Agent grants

Project Agent grants expire and are limited to one saved context pack plus explicit read and suggestion-stage scopes. Tokens are shown once and can be rotated or revoked. They cannot access export, provider mutations, billing, DNS, secrets, production controls, or workspace-wide activity history.

Error and abuse protection

Sensitive API routes use trusted-origin checks, request-size limits, rate limits, and fail-closed authentication. Sentry is optional and uses strict event scrubbing when configured. Cloudflare Turnstile is optional for anti-abuse challenges. Vercel Analytics and Speed Insights provide product and performance telemetry.

Storage and recovery

Workspace records use Neon/PostgreSQL. Participating forms save immediately to versioned IndexedDB and can sync an allow-listed workspace draft to the server. Both recovery layers expire after seven days of inactivity; IndexedDB quota or privacy-mode failures are reported in the form. Authenticated pages are not cached for offline reload. Private project media uses private Vercel Blob storage when configured. Workspace deletion revokes provider credentials and Project Agent grants, locks access, and provides a 30-day recovery window before records become eligible for scheduled permanent purge.

Report a concern

Email hello@huske.io with a concise description of a suspected security or privacy issue. This page describes current beta safeguards; it is not a compliance certification or penetration-test claim.

Report a security concern