Security

Reminix runs code your team wrote, with your API keys. Here is how it keeps both safe. If your security team has a questionnaire, send it to security@reminix.com.

Where your code runs

Each version of a script runs in its own isolated sandbox. It can't reach other scripts, your workspace's data, or Reminix itself; it sees only its inputs. It has no network access unless its version lists the hosts it may call, and then it can reach only those, over HTTPS, with every request written to the run's log. A run has a time limit, and a long run can be cancelled.

Secrets

Reminix encrypts API keys at rest (AES-256-GCM, with a key per workspace). They're write-only: once you save one, nothing shows the value again, not the app, the API, the command line or an agent. Reminix attaches a secret to a request only when the request goes to a host that secret allows, so the code doesn't hold it. Code can read a secret only if its owner turns that on.

Who can do what

What Reminix stores

Your account and workspace details; each script's code, versions and settings; and every run: its inputs, output, log, and who started it from where. Reminix keeps run logs for your plan's period (7, 30 or 90 days), and keeps each run's record while the workspace exists.

Where it's stored

Code runs on Cloudflare's network. Reminix keeps script code and run logs in object storage (Cloudflare R2). It keeps accounts, settings and run records in a managed PostgreSQL database (Neon) in a single region, with the provider's point-in-time recovery for backups. We encrypt all traffic in transit (TLS 1.2 or later, with HSTS), and data at rest.

Signing in

People sign in with an email and password, checked against known breaches, and can turn on two-factor authentication. We store only hashes of passwords, API keys and personal access tokens. We show a key or token once, when you create it, and each carries scopes. Our own staff must use a verified address and two-factor authentication to reach customer data, and we record every staff action on customer data.

Audit log

Reminix records these in an append-only log that workspace owners can read: membership changes, script access and approval settings, approvals and publishes. It also records secrets saved or deleted (never their values), and API keys and access tokens created or revoked.

Sub-processors

Compliance

We haven't completed a third-party audit (such as SOC 2) yet. We can sign a data processing agreement on request. Ask us about our plans.

Reporting a vulnerability

Please report security issues privately to security@reminix.com, also listed at /.well-known/security.txt. Include what you found, where, and how to reproduce it. We reply within two business days, and ask for reasonable time to fix an issue before anyone makes it public.