Security

Built with security in mind

Give your teams the controls and visibility they need to manage infrastructure across development and production environments.

Controls

Security controls in the platform

Authentication

Secure sign-in for your team and authenticated access to every API request.

Role-based access

Assign roles so each team member sees and changes only what they need.

Audit logs

Review who changed what, and when, across your workspace.

Environment management

Keep sandbox and production isolated with separate configuration.

API credentials

Create, scope, rotate, and revoke keys per environment.

Activity monitoring

Track requests, webhook deliveries, and workflow runs in real time.

Practices

How we protect your workspace

  • Encryption in transit. All API and dashboard traffic is served over HTTPS (TLS).
  • Least-privilege access. Roles and scoped API credentials limit what each user and key can do.
  • Environment isolation. Sandbox and production have separate credentials and data.
  • Signed webhooks. Every delivery can be verified with a per-endpoint secret.
  • Auditability. Workspace changes and API activity are logged and reviewable.

Disclosure

Report a vulnerability

If you believe you have found a security issue, please email info@lithicapp.com with a description and steps to reproduce. We review every report and will respond as quickly as possible. Please do not publicly disclose the issue until we have had a chance to address it.

Questions about security?

Talk with our team about access controls, environments, and how LithicApp fits your security requirements.