MarlinVix for WordPress is now in early access. Create a workspace

Security posture

Controls applied at the boundaries that matter.

Security is implemented as layered application and data controls. This page describes current design choices without claiming an external certification or absolute protection.

Tenant authorization

Membership and role checks are performed server-side for workspace resources.

Credential handling

License secrets are stored as hashes. Supported BYO provider credentials are encrypted before storage.

Signed requests

Plugin calls use HMAC signatures, timestamp windows and nonce replay protection.

Safe retrieval

Outbound website requests use URL validation, network restrictions, timeouts and response-size bounds.

Scoped data

Row-level controls and tenant-prefixed caches reduce cross-workspace access risk.

Auditability

Security-sensitive operations emit structured audit or security events without logging raw secrets.

Report a security issue responsibly. Do not include credentials or personal information in an initial report. Review the responsible disclosure guidance before contacting us.