01 · Encryption
Encryption at every hop.
TLS 1.3 in transit. AES-256 at rest. Per-tenant data-encryption-key rotation on a 90-day cadence. Webhook payloads HMAC-SHA256 signed (X-Challenge-Token header, constant-time comparison) so the only way to forge a candidate submission is to leak a per-repo secret that doesn't exist outside the runner.