Security

Credentials

Transport

All public API traffic uses HTTPS (https://api.hydracept.com).

Least privilege

Bind provider credentials to the project/environment that needs them. Use separate machine credentials for CI and production when you can.

Consumer boundary

For generation handled by Hydracept, route work through the Hydracept API instead of calling provider SDKs directly. See Integrating safely.

Reporting

Report security issues to support@hydracept.com.