Nimbrivo Cloud is being built in publicExplore the reviewed marketplace

Security architecture

Protection below
the interface.

Nimbrivo Cloud treats identity, tenant isolation, package integrity, provider access and operational evidence as system boundaries—not marketing badges.

01 / Identity

Self-hosted operator authentication

Password hashing, bounded lockout, opaque digest-only sessions, TOTP, recovery codes, passkeys and provider-neutral OIDC are implemented boundaries.

02 / Authorization

Least privilege at every mutation

Server actions and service methods reauthorize at the data-owning boundary, including inside transactions for sensitive state changes.

03 / Tenancy

Tenant identity follows the data

Site and organization ownership are explicit in durable records and validated by services instead of relying on URL shape.

04 / Secrets

Encrypted, scoped and never read back

Sensitive provider values use authenticated encryption and write-only management patterns with key-rotation support.

05 / Network

Outbound traffic fails closed

Provider and webhook destinations reject unsafe addressing, credentials and redirects, with DNS validation and bounded response handling.

06 / Evidence

Security-sensitive changes leave history

Immutable audit and event records retain who requested a change, the durable transition and the bounded outcome.

Defense in depth

Sensitive work crosses several gates.

No single UI check is treated as the security boundary. Authorization, validation, atomic state changes and audit evidence remain in the services that own the data.

  1. 01Authenticate the identity
  2. 02Resolve durable membership
  3. 03Authorize the exact capability
  4. 04Validate and commit atomically
  5. 05Retain bounded audit evidence

Build on a stronger foundation

Give publishing teams a safer operational foundation.

Security controls remain explicit, testable and independent of the visual interface.