Security

Credentials

Transport

All public API traffic uses HTTPS (https://api.hydracept.com).

Least privilege

Bind provider credentials to the project/environment that needs them. Use separate machine credentials for CI and production when you can.

Consumer boundary

When Hydracept owns generation execution, route work through Hydracept instead of calling provider SDKs directly. See Consumer Boundary.

Reporting

Report security issues to support@hydracept.com.