vector.8n.ai

Security & Architecture

How we protect customer data, secrets, and uptime. Honest about what's shipped vs roadmapped — see /roadmap for timing.

Architecture overview

Edge
Cloudflare Tunnel (uhas-next) · TLS 1.3 · DDoS protection · WAF rules
live
Application
Next.js 15.5 + React 19 · CSP headers · httpOnly session cookies · CSRF tokens on mutating endpoints
live
AI Gateway
Server-side Anthropic API calls · API keys in /etc/vector-8n.env (chmod 600 root) · key never reaches browser
live
Storage (free/team)
JIB1 datacenter Pattaya · pg-ha 3-replica quorum sync · R2 WAL archive · daily backup · 2-second RTO · 0 RPO failover verified
live
Storage (enterprise on-prem)
Customer-managed Kubernetes via Helm chart · zero data leaves customer infra
available
Real-time collab
Yjs WebSocket (vectorws.8n.ai → port 3141) · CRDT conflict resolution · room ACLs (v1.47+)
live
Audit log
Per-action records (actor + ts + target + meta) · CSV/JSONL export · 90-day retention (Team) / unlimited (Enterprise)
live

Security practices

Encryption at rest
AES-256 for all document data in Postgres + R2 backups
Encryption in transit
TLS 1.3 minimum · HSTS preload · forward secrecy
Authentication
Magic-link email · session tokens 30-day expiry · enterprise SSO/SAML (Q3 2026)
Authorization
5-role workspace permissions (owner/admin/editor/reviewer/viewer) with wildcard policy engine
Secret management
All API keys in OS-level env files (chmod 600 root) · never in source · never in client bundles · HashiCorp Vault target for v1.48+
Vulnerability response
[email protected] · 24h triage · public CVE disclosure within 30 days of patch
Dependency scanning
pnpm audit on every CI run · Dependabot weekly · Snyk planned for v1.48
Code review
All production deploys reviewed before deploy · git-signed commits · audit trail in /changelog

Compliance

SOC2 Type II
Scheduled Q3 2026
GDPR
Compliant (DPA on request)
Thailand PDPA
Compliant
HIPAA
Not applicable (not a medical service)
PCI-DSS
Not applicable (no card data stored)
ISO 27001
On roadmap 2027

Contact

Security questions: [email protected] · Sales / enterprise procurement: [email protected] · Vulnerability disclosure: PGP key fingerprint at /.well-known/security.txt