Separate public traffic
Customer tunnel hosts are isolated from the control, authentication, dashboard, and administration origin.
Security model
Security documentation must explain real trust boundaries, capture defaults, connector permissions, abuse controls, and data handling without implying certifications that do not exist.
See how it worksCustomer tunnel hosts are isolated from the control, authentication, dashboard, and administration origin.
Web, control, relay, worker, database, deployment, migration, and connector responsibilities use separate privilege boundaries.
Forwarded requests, headers, redirects, payloads, and replay inputs are validated at every boundary.