Security
Security is built into LocalMind's structure, not bolted on. This page summarizes the guarantees the core enforces.
Authentication
- Passwordless — email one-time codes, passkeys and Google / GitHub social sign-in. There is no password to phish or leak.
- Passkeys (WebAuthn) — phishing-resistant, hardware-backed, and a strong second factor in their own right.
- Two-factor (TOTP) — optional authenticator-app 2FA with backup codes.
- Step-up elevation — sensitive actions (delete project, transfer ownership, mint/revoke an API key, rotate a webhook secret, assign a system role, any platform override) require a fresh strong-factor re-verification.
- Sessions —
httpOnly+Secure+SameSitecookies; sign-out is all-devices and a suspended account's sessions are invalidated immediately.
Tenant isolation
- Project-scoped data access goes through a base repository whose query interface requires a project id at the type level — a query without one can't compile.
- Route guards resolve and verify the caller's project scope before the handler runs; repositories trust only that scope, never a project id from the request body.
- Cross-tenant or non-existent resources return 404, never leaking whether a resource exists.
API surface
- CSRF protection on state-changing requests plus same-origin
SameSitecookies. - Rate limiting per session and per API key.
- Input validation on every endpoint via typed DTOs.
- Security headers (CSP,
X-Frame-Options,X-Content-Type-Options,Referrer-Policy) on all responses. - HMAC-signed webhook deliveries with SSRF protection — see Webhooks.
Data protection
- All traffic over TLS; secrets at rest (webhook secrets, 2FA secrets) encrypted with a rotatable key.
- Parameterized queries throughout — no string-built SQL.
- One-time secrets (API keys, webhook secrets) are shown once and stored only as a hash or hint.
Accountability
Every sensitive action — and every use of the cross-tenant override — is written to the audit log.
Reporting vulnerabilities
Please report security issues responsibly to the security team rather than opening a public issue.