OjasBase.
Security + trust

Control-plane authority stays separate from customer workloads.

Specific architecture, scoped access and controlled operations. Security capabilities are described at their verified source-level state; real-host pilot gates still apply.

Project secrets

Production secrets belong outside source code.

Store API keys, database credentials and runtime configuration at project/environment level. Sensitive values stay separate from source and are injected into authorized workloads.

Project environmentIllustrative · Production
DATABASE_URL••••••••••••
JWT_SECRET••••••••••••
OPENAI_API_KEY••••••••••••
RAZORPAY_KEY_SECRET••••••••••••
PRIVATE_KEY••••••••••••

Values hidden after save. No real credentials appear in this example.

Minimize secret exposure.

OjasBase uses encrypted storage, scoped access and controlled runtime injection. Source tests do not establish that a real deployment is immune to leaks.

  • AES-256-GCM encryption in source
  • Project + environment + service scoping
  • Normal API responses omit plaintext
  • Role-protected changes and version history
Capability state

Trust points with explicit boundaries.

ControlStateBoundary
Encrypted project secretsImplemented source · PilotEnvelope encryption; operator key management and recovery remain host responsibilities.
Environment scopingImplemented source · PilotProduction, Staging and Preview use explicit environment identity.
Build / runtime scopeImplemented source · PilotScoped delivery with immutable release bindings.
Bulk .env importImplemented source · PilotFeature-gated parsing/import; keep raw files outside source.
Hidden values + versionsImplemented source · PilotMetadata omits plaintext; encrypted secret version history.
Resource bindingsImplemented source · PilotExplicit environment-to-resource variable mapping; no silent Production inheritance.
Private database accessImplemented source · PilotAuthenticated control plane and private managed-resource executor.
Read-only SQL defaultImplemented source · PilotEnforced database/session restrictions, not frontend regex alone.
Restricted write modeImplemented source · PilotAuthorized elevated operations with Production safeguards.
Bounded queriesImplemented source · PilotTimeout, row/payload limits and query cancellation.
Tenant checks + auditImplemented source · PilotTenant-owned targeting and metadata audit; result rows excluded.
Log redactionImplemented source · PilotSecret filtering is implemented; validate application/build leakage on the host.
TLS in transitControlled pilot · Host validationPublic HTTPS via Caddy; universal private-traffic encryption is not claimed.
Migration direction

Move configuration without committing it to Git.

Feature-gated .env import parses entries into encrypted project configuration. The raw .env file should never become a stored source artifact.

Pilot

Production, Staging, Preview

Keep test credentials separate from production. Environment-aware build/runtime scopes and versioned secrets are implemented in source; host validation still applies.

Payment-provider secrets

Payment API credentials can be project secrets. Customer card data belongs with the payment provider and should not be stored as an application secret.

Database trust

Private data. Explicit access.

Pilot

Private managed networking

Managed Postgres uses project private networking and encrypted generated credentials. Connection reveal requires authorization. Backup and restore remain controlled resource operations.

Implemented source · Pilot

Controlled Database Studio

Database Studio mediates authenticated access through the control plane and private executor. Read-only mode, bounded queries, cancellation and metadata-only audit are implemented in source. Normal console access does not require publishing PostgreSQL to the internet.

SQL can change or delete application data. Production write access requires explicit authorization; query results and sensitive SQL values must stay out of platform logs. Source implementation is distinguished from live-host release validation; controlled Pilot gates still apply.

Platform boundaries

Controlled pilot, explicit responsibilities.

01

Scoped access

Organization RBAC, tenant ownership checks, organization API tokens and unique worker credentials.

02

Protected control plane

Caddy administration is isolated. Operator fleet APIs are separate from customer project APIs.

03

Safe runtime limits

Resource reservations, PID limits, read-only defaults and restricted pilot networking.

04

Recovery

Release rollback and managed Postgres backup/restore workflows. Verify restoration on the real host.

Dedicated workers retain Docker-socket authority. Shared pilot networking is not a claim of hostile-public multi-tenant isolation. Live-host isolation, DNS/TLS, backup/restore and restart gates must be proven before widening access.

Read security architecture

Enterprise direction

Integrations when the platform is ready.

External secret managers · FutureBring-your-own KMS · FutureVault integrations · FutureSSO · Future
Your next application

Build the product.
Keep infrastructure from
becoming the product.

Start with one application. Add data, domains and capacity as it grows.