1. Cloud Infrastructure & Encryption
Skill-Forge runs on enterprise Google Cloud Platform (GCP Cloud Run and Firebase) infrastructure. Our security architecture adheres to strict cloud security standards:
Encryption in Transit
All web, API, and WebSocket requests enforce HTTPS / TLS 1.3 with HSTS preloading enabled.
Encryption at Rest
Database records, user profiles, and saved project states are encrypted using AES-256 cloud key management.
2. Isolated Code Runner Security
Interactive code execution poses unique security challenges. To prevent arbitrary code execution from impacting host infrastructure or other tenant sessions:
- Container Isolation: User code runs inside ephemeral containers with dropped kernel privileges and read-only root filesystems.
- Strict Quotas: Memory limits (512MB), CPU timeouts (5s max execution), and restricted system call filters (seccomp) prevent runaway processes.
- Network Egress Rules: Execution sandboxes run in isolated VPC subnets without access to internal control plane services.
3. Access Controls & Authentication
User passwords are stored using adaptive bcrypt/Argon2 hashing algorithms. We support OAuth 2.0 single sign-on (SSO) via GitHub and Google to prevent credential reuse risks.
4. Responsible Disclosure Program
Skill-Forge welcomes security researchers and white-hat community members to report potential vulnerabilities under our Responsible Disclosure policy.
Email full reproduction steps and proof-of-concept details to security@skillforge.dev. Please refrain from automated spam scanning or public disclosure prior to fix verification.
5. Incident Response & Monitoring
Our automated telemetry logs system anomalies 24/7. In the event of a verified data breach, Skill-Forge will notify impacted users within 72 hours in compliance with global security mandates.
Was this legal document clear & helpful?
Your feedback helps us keep our policies transparent.