Skip to content

Security

Security is built into how Subment works.

Subment holds subscription and access information that can be sensitive. This page documents the protections implemented today, their boundaries and the things Subment does not claim.

Data encryption

Traffic between your browser and Subment uses HTTPS. At rest, each secret is encrypted individually with AES-256-GCM before storage. Each workspace has its own encryption key, protected by a managed key service.

Subment is not zero-knowledge. The service can decrypt a secret when an authorized person asks to reveal it or generate a TOTP code. This enables the product’s shared-access workflows, but is an important limit to understand.

Authentication and account protection

Account passwords are stored as one-way Argon2id hashes. Two-factor sign-in is available. Session tokens are stored in httpOnly cookies, and sign-in and sensitive actions are rate-limited. Revealing or copying a login, and generating a 2FA code, requires a recent sign-in confirmation.

Credential and TOTP protection

Credentials are listed masked and revealed only when an authorized person requests them. TOTP secrets and recovery codes are encrypted like other secrets. The activity log records sensitive actions such as credential reveals, copies and code generation with who and when; it never records the secret itself. Exports never contain passwords, keys or 2FA codes.

Workspace isolation and access control

Workspaces separate subscriptions, members and their encryption keys. A person’s workspace role and their View, Use or Manage permission on a subscription control access, with checks performed on the server for each request. Access to one workspace does not extend to another. Guests can be limited to what has been shared with them.

Security principles and transparency

  • Least privilege: roles and per-subscription permissions set access boundaries.
  • Secure defaults: secrets are masked until requested, and sensitive actions require recent sign-in confirmation.
  • Data minimization: payment method records do not store a full card number.
  • Auditability: sensitive access is recorded without recording the secret.
  • Clear limits: Subment has no security certifications or independent audit reports to publish yet, and hosting and data-location details will be published when final.

Responsible disclosure

If you believe you have found a security issue, report it to [email protected]. Please do not include passwords, API keys, TOTP secrets or other sensitive customer data in a report. There is no formal bug bounty or disclosure programme at this time.

Bring the details and access together.

Subment is free during early access.

Get early access