The fine print, up front

Less to hand over.
Not invincibility.

Separation reduces what you expose. It does not make an agent, a browser or a website trustworthy. This is a description of the implementation’s boundaries, not a security certification.

Storage & access

Protect stored secrets.
Limit future reads.

Encryption at rest

Passwords, verification codes and verification/reset links are encrypted with AES-256-GCM before storage in Aliasport’s D1 database. Authorized clients can still receive plaintext.

Leases are not remote erasers

A lease records authorization and audit metadata. Its timer cannot remove a password from a client’s memory, logs or copies.

Revocation has a boundary

Revoking an identity prevents future credential and mail-secret reads through the broker. It does not close target-site accounts, invalidate existing browser sessions or recall plaintext.

Separate service boundaries

Aliasport and Signalport use separate Workers, D1 databases and access configuration. The console calls APIs from its server boundary; it does not hand API service tokens to the browser.

Data handling

Mail is verification.
Not an inbox archive.

The MVP processes incoming mail to extract short-lived verification material and retains mail metadata. It does not store raw MIME, attachments or full mail bodies. Expiration and cleanup apply to the extracted secrets.

The public website contains illustrative records only. It adds no analytics, signup forms or credential collection. Following a console link takes you to a separate restricted service.

Operators must recheck access controls and email delivery after configuration changes. Release verification is not a security certification or an uptime guarantee.

Non-goals

Some tasks
do not belong here.

  • No personal, financial, administrator or recovery accounts.
  • No CAPTCHA bypass, anti-abuse evasion or bulk account creation.
  • No promise that browser automation complies with a site’s terms; the operator must check.
  • No assumption that a reviewed source is permanently reliable.

Keep the stakes low. Use identities created specifically for permitted automation, and treat every plaintext handoff as a disclosure to that client.

Availability is a separate question

Check the preview scope.

Availability & access