Security model
The invariants that protect workspaces, applications, end users, and external side effects.
Linea is multi-tenant and executes user-defined workflows that can reach models and external services. Security is therefore expressed as explicit boundaries and independently scoped capabilities, not one all-powerful token.
Core invariants
- Every tenant-owned read and write is scoped to a workspace.
- Application and Workspace Keys have different authority and are not substitutes.
- End-User Sessions are short-lived, subject-bound, audience-bound capabilities.
- Public browser requests prove possession with DPoP and enforce trusted origins.
- Approval ownership follows the approver identity, not an ephemeral browser session.
- A Decision is immutable and separate from the Approval Request it answers.
- Provider and connector secrets remain on trusted server boundaries.
The planned Connections milestone adds another invariant: an external side effect requires consent for the exact Action Intent or a covering policy. That connector enforcement is not part of the current release.
Reporting vulnerabilities
Do not open a public issue for a vulnerability. Follow the repository
security policy and
send reports to contact@getlinea.app.