VVislyt

Security

Tenant isolation and cost controls built into the workflow

Vislyt uses workspace-scoped authorization, server-side provider calls, hashed secrets and defensive crawling. This page describes implemented controls, not a certification.

Access control

Private resources require authenticated workspace membership and role checks. Global administration is separated from workspace permissions.

Secret handling

Provider and Stripe secrets remain server-only. API keys are stored as hashes; sensitive refresh tokens can be encrypted with the application encryption key.

Request defenses

Zod validation, secure cookies, security headers, webhook signatures, idempotency and MySQL-backed rate limits protect key boundaries.

SSRF-resistant crawling

The crawler blocks private, loopback, link-local and metadata endpoints, validates DNS, limits redirects, response size and time, and revalidates redirect hosts.

AI budget hard stops

Preflight estimates check trial and global limits. A hard limit blocks new provider calls without hiding existing results.

Start with evidence you can inspect.

Run a free visibility check first, or start a 14-day trial to build a repeatable tracking workflow.