Security
Tenant isolation and cost controls built into the workflow
Vislyt uses workspace-scoped authorization, server-side provider calls, hashed secrets and defensive crawling. This page describes implemented controls, not a certification.
Access control
Private resources require authenticated workspace membership and role checks. Global administration is separated from workspace permissions.
Secret handling
Provider and Stripe secrets remain server-only. API keys are stored as hashes; sensitive refresh tokens can be encrypted with the application encryption key.
Request defenses
Zod validation, secure cookies, security headers, webhook signatures, idempotency and MySQL-backed rate limits protect key boundaries.
SSRF-resistant crawling
The crawler blocks private, loopback, link-local and metadata endpoints, validates DNS, limits redirects, response size and time, and revalidates redirect hosts.
AI budget hard stops
Preflight estimates check trial and global limits. A hard limit blocks new provider calls without hiding existing results.
Start with evidence you can inspect.
Run a free visibility check first, or start a 14-day trial to build a repeatable tracking workflow.