Regressa

Security

Authentication and authorization

Data handling

Tenancy isolation

All reads and writes are scoped by project_id derived from the session or the API key. No endpoint accepts a project id from the caller. Cross-project references (templates, evals in alert rules) are validated against the active project before use.

Reporting a vulnerability

Email security@regressa.dev. Please do not open public issues for security reports. We aim to acknowledge within two business days.