← Back to home
Security
Security
Enterprise-grade controls protect every decision and every sensitive dataset processed by HumanLayer.
HumanLayer handles decisions that commit professionals and organizations. This page describes the measures actually in place; it is updated whenever they change.
Infrastructure
- Encryption in transit: all traffic uses HTTPS (TLS 1.2 and above, TLS 1.3 when the browser supports it), with HSTS.
- Secrets encrypted at rest: two-factor secrets are encrypted with AES-256-GCM; API keys are stored only as SHA-256 fingerprints; passwords are hashed with scrypt.
- Hosting: SOC 2 Type II certified cloud infrastructure. Server code is not published with the website.
- Isolation: each API key only reaches its own requests, each client only its keys and decisions, each Sentinel only the cases assigned to them.
- Browser: strict Content Security Policy, framing forbidden, portals excluded from indexing.
Authentication and access
- Two-factor authentication (TOTP) required for every Sentinel: it cannot be disabled, only renewed, and a code that was already used is rejected.
- Administrator access protected by a password and a mandatory second factor.
- Separate roles (administration, Sentinels, clients), each with its own session signing secret.
- Sessions last 12 h at most, with automatic logout; the account status is checked on every request, so a suspension takes effect immediately.
- Attempt limits: temporary lockout after 5 failed logins on an account, plus limits per IP address and per API key.
- Audit log of logins and sensitive actions (decisions, API keys, authorizations, two-factor changes), exportable.
Decision integrity
- Every decision is signed (Ed25519): identifiers, verdict, fingerprint of the justification, Sentinel pseudonym and timestamp. The public key is published (
/api/v1/decision-key): any tampering is detectable. - A single final decision per request, recorded atomically.
- Signed webhooks (HMAC-SHA256, secret specific to each API key); callback URLs limited to HTTPS and public hosts.
- SLAs monitored continuously: any breach is reported and the request is reassigned automatically.
Sentinel verification
- Identity verification before activation
- Validation of professional qualifications and authorizations
- Suspension possible at any time, effective immediately
- Full traceability of each decision
Regulatory compliance
- GDPR (General Data Protection Regulation)
- Law 25 (Quebec)
- SOC 2 Type II (certification in progress)
- ISO 27001 (planned)
Vulnerability reporting
If you discover a security vulnerability, write to us at humanlayer@probalink.com. We commit to handling any report within 24 hours.
Testing and reviews
- Automated tests of authentication, two-factor authentication, attempt limits, decision signatures and data isolation, run on every change.
- Security review of the code (latest: September 2026).
- Penetration testing by an independent third party: planned.