Managed Cial security model
- Each Managed Cial workspace runs with isolated lifecycle and storage.
- The workspace does not receive billing, identity-provider, database-administration or fleet-orchestration credentials.
- Control-plane requests derive identity and ownership from verified server-side state rather than trusting workspace input.
- Short-lived, replay-resistant proofs authenticate privileged workspace-to-service calls.
- Account verification, rate limits, abuse checks and global capacity controls protect public onboarding.
Protect your Managed Cial workspace
Give agents only the credentials and external permissions needed for the task. Review destructive actions, rotate exposed credentials, keep important source and data backed up, and use additional controls appropriate to the sensitivity and regulatory requirements of your workload.
Self-hosted OpenCial
When OpenCial source is separately released, a self-hosting operator will be responsible for securing its deployment, network and access controls; managing secrets and integrations; installing updates; maintaining backups; responding to incidents; and giving its own users appropriate legal and privacy notices. The Managed Cial control-plane protections described above do not automatically apply to an independent OpenCial deployment.
Report a vulnerability
Email security@cial.app with a clear description, affected surface, reproduction steps and impact. State whether the report concerns Managed Cial or OpenCial. Do not include live credentials or unnecessary personal data. We will acknowledge valid reports and coordinate remediation before public disclosure.
Safe-harbor boundaries
Use accounts and data you own, avoid privacy violations and service disruption, stop once you have demonstrated the issue, and give us reasonable time to remediate. Denial of service, social engineering, spam, physical attacks and accessing another user’s data are out of scope. No bug-bounty payment is promised unless agreed in writing.
Policy scope
This reporting policy covers Managed Cial web and control-plane surfaces and, once released, OpenCial source maintained by Techforces. Third-party services and independently modified forks remain subject to their operators’ disclosure processes.