CoderXP
CoderXPM1
Trust & Architecture

Security Architecture

Technical explanation of CoderXP data isolation, BYOK key encryption, and execution boundaries.

Legal Review Notice

Draft security documentation. Formal third-party compliance certifications (SOC 2, ISO 27001) will be documented here once verified.

AES-256-GCM Encryption at Rest (Planned)

All user-submitted API credentials stored in the BYOK vault will be encrypted server-side using AES-256-GCM before database write. Secret values will never be exposed in browser telemetry or public logs. This is a planned architecture specification, not yet implemented.

Execution Container Isolation (Planned)

Client previews will run inside sandboxed browser WebContainers. Backend operations will execute inside ephemeral, isolated server sandboxes destroyed upon completion. This is a planned architecture specification.