Search

Search for a command to run...

Security

How we protect your keys, your data, and your users — built for Algeria's compliance requirements from the start.

Encryption in transit

All traffic to OpenDunes is served over TLS. API keys are transmitted as bearer tokens over encrypted connections only.

API key handling

Keys are hashed at rest and shown once at creation. You can revoke or rotate any key instantly, and scope keys per workspace.

PII redaction

A redaction pipeline scans request payloads for personal data before they leave our edge, aligned with Algeria's Law 18-07.

Audit trails

Sensitive account and billing actions are recorded to an append-only audit log for accountability and compliance.

Data residency

Request routing and storage are designed around in-country data residency requirements, not an afterthought.

Least privilege

Provider secrets are server-side account secrets, never exposed to clients. Services access only what they need.

Reporting a vulnerability

Found a security issue? Email security@opendunes.com with the details and steps to reproduce. Please give us a chance to fix it before public disclosure. See also our Privacy Policy and Terms.