> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pult.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# Security

> What Pult can and can't do with your app, and the controls you have over it.

## Your app keeps control

Pult never connects to your database or your infrastructure. Everything it knows about your records comes from functions in your app, and everything it does to them is an action your app runs and can refuse. If you remove an action from your code, nobody can run it, whatever their role.

## Signed both ways

Every request between your app and Pult is signed with your environment's key, using HMAC-SHA256 over the method and path, a timestamp, a one-time nonce and the body. Pult refuses requests that are unsigned, altered, more than five minutes old or seen before, and the SDK applies the same checks to requests from Pult. Keys are stored encrypted, can be rotated at any time, and each environment has its own.

## Permissions live in code

Roles, and which inboxes, resources, actions, pages and flags they grant, are defined in your repository and reviewed like any other change. `pult diff` shows who gains or loses which permission before you deploy. People are assigned roles in the console; agents get exactly one role each.

## Guardrails on actions

Actions and flags can ask for confirmation, a fresh sign-in, or a second person's approval, and you choose which in code. Triage can only run actions you've marked safe for it, never ones that need an approval. See [Actions](/build/actions#guardrails).

## Sensitive values

Values marked sensitive never reach the browser until someone allowed to reveals them, and every reveal is recorded. Triage never sees them. See [Blocks](/build/blocks#sensitive-values).

## Accounts

There are no passwords to leak or reuse. People sign in with a passkey or a one-time code sent to their email, so every account belongs to someone who controls its address. Codes work for 10 minutes and a few tries, and repeated attempts from one address are slowed down. Dangerous actions ask for a fresh passkey or code first.

## A record of everything

Every action, approval, flag change, state change, note, reveal, deletion and deploy is kept in the timeline of the item or record it touched and in the environment's audit log, with who did it.

## Email

Pult never sends mail from your domain. Customer email goes through your own app and provider. See [Email](/build/email).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.