BlinkHost
BlinkHost

Platform security

Protection across accounts, projects, previews and releases.

BlinkHost protects the application delivery lifecycle with secure account sessions, workspace and project access controls, short-lived preview capabilities, guarded secrets, scanned project uploads, verified release artifacts, encrypted connections and operational security evidence. These controls are designed to help developers and agencies build and operate customer applications without exposing reusable infrastructure credentials.

Protect access to projects and resourcesKeep preview credentials temporary and purpose-boundPublish only identified, verified release artifacts
01

Account and workspace access

Secure browser sessions and server-enforced workspace permissions protect account, project and billing operations.

02

Project resource isolation

Databases, assets, modules and operational data remain associated with the project and workspace that own them.

03

Secrets and preview access

Secrets are kept out of public frontend code, while eligible preview resources use short-lived, purpose-specific access instead of reusable credentials.

04

Verified builds and releases

A deployment must reference the verified artifact produced for the release; an upload or build message alone is not treated as production proof.

05

Uploads and application assets

Project uploads are subject to file, size and storage limits plus security scanning before they become available to the application workflow.

06

Encrypted delivery and domains

BlinkHost serves platform and managed-domain traffic over HTTPS and guides domain activation through certificate and ownership checks.

07

Operational security evidence

Supported logs, deployment state and audit evidence help authorised workspace members investigate changes and production behaviour.

08

Responsible disclosure

Security researchers and customers can report a suspected vulnerability through the published security disclosure process.

Common questions

Clear answers about platform security.

How does BlinkHost protect project access?

BlinkHost requires an authenticated account and enforces workspace and project permissions on protected operations. Access is checked by the service, not only by what the interface displays.

Are preview credentials the same as production credentials?

No. LiveStack Preview is separate from production deployment. Eligible preview resources use short-lived, purpose-specific capabilities so a browser preview does not receive a reusable production credential.

How are backend modules protected before deployment?

Rust, Go and Python backend modules follow a build and verification path. Deployment requires the identified verified artifact for the release rather than trusting an unverified upload.

How should a security concern be reported?

Use the BlinkHost Security and Vulnerability Disclosure process in the Legal Centre. Do not include passwords, access tokens or unrelated personal data in a report.

Continue exploring

Legal centreSecurity disclosure