Security

Mainbrella isolates agent workloads and checks account ownership at the API boundary. This page describes the controls implemented today, along with the limits you should account for.

Workload isolation

Mainbrella runs Linux containers on Cloudflare Containers. Cloudflare documents that each instance runs in a Firecracker microVM with its own kernel and network. See Cloudflare's container runtime architecture.

Mainbrella selects the account's containers, images, resource size, and deadlines on the server. Client-supplied ownership or entitlement overrides are not accepted. Isolation does not prevent code from reading secrets you give it or sending data to external services.

Authentication and credentials

Website accounts use verified Google sign-in. Sessions use Secure, HttpOnly cookies and hashed tokens. Named API keys are shown once, stored as SHA-256 hashes, and can be revoked. Browser mutations and terminal connections require a trusted Origin.

API keys authorize workload operations, not credential management or billing. An invalid explicit Bearer credential cannot fall back to a browser cookie. SSH access tokens are hashed, time-limited, and tied to the selected container generation.

Generation checks and execution bounds

HTTP execution and file operations require the exact container ID and creation timestamp. This prevents a stale request from acting on a replacement instance in the same slot. Include the generation when stopping a container or issuing SSH access too.

Commands, output, files, concurrent operations, session duration, and idle time are bounded by server policy. These controls limit resource use; they are not an application-level guarantee that an agent's commands are safe. See limits.

Data and network access

The public website and API use HTTPS. Container files are ephemeral and are lost after stop; there are no persistent workspaces or customer snapshots. Keep independent backups and remove unnecessary secrets from workloads.

Outbound internet access is enabled for packages and external services. There are no customer-configurable egress policies or guaranteed residency regions today. Your code controls which destinations receive its data. Do not submit regulated data without prior written agreement.

Infrastructure providers

Cloudflare provides hosting, compute, and database infrastructure; Google provides sign-in; Stripe handles payments. Mainbrella does not receive full payment card details. Account, billing, and support records have a separate lifecycle from temporary container files; see the Privacy Policy.

For provider purposes and processing locations, see Providers and subprocessors. The Trust center also covers continuity and DPA availability.

Assurance and availability

Mainbrella does not claim SOC 2 or ISO 27001 certification, an independent penetration-test attestation, or a self-service uptime SLA. Provider certifications and service commitments do not automatically apply to Mainbrella. See service status for published observations and incidents.

Report a vulnerability

Email security@mainbrella.com. Our vulnerability disclosure policy explains scope, permitted testing, and how we handle good-faith reports.