EvoHub Docs Sign in
DeutschDE
Diese Seite liegt noch nicht auf Deutsch vor und wird auf Englisch angezeigt.

Security and privacy

Security at EvoHub

Mit KI verwenden
Als Markdown anzeigenDiese Seite als reiner Text, zum Einfügen in ein KI-Tool In Claude öffnenClaude Fragen zu dieser Seite stellen In ChatGPT öffnenChatGPT Fragen zu dieser Seite stellen
Mit Cursor / VS Code / Claude verbindenDiese Dokumentation aus Ihrem KI-Tool durchsuchen und lesen (MCP-Server)

URL des MCP-Servers

https://docs-dev.evohub.io/mcp

Claude Code

claude mcp add --transport http evohub-docs-docs https://docs-dev.evohub.io/mcp

Claude (claude.ai und Claude Desktop): Einstellungen → Konnektoren → Benutzerdefinierten Konnektor hinzufügen und die URL oben einfügen.

Claude Desktop — claude_desktop_config.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote",
        "https://docs-dev.evohub.io/mcp"
      ]
    }
  }
}

Cursor — ~/.cursor/mcp.json

{
  "mcpServers": {
    "evohub-docs-docs": {
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

VS Code — .vscode/mcp.json

{
  "servers": {
    "evohub-docs-docs": {
      "type": "http",
      "url": "https://docs-dev.evohub.io/mcp"
    }
  }
}

This page describes the measures that protect your EvoHub account and your organization's data, and the settings you control. It only lists what EvoHub actually does today.

Encryption in transit

All traffic to EvoHub, including the console, the API and the mobile apps, is encrypted in transit with TLS 1.2 or higher.

Passwords

  • Passwords are hashed with bcrypt, a salted one-way hash, before they are stored. EvoHub never stores or logs a password in plain text, and nobody at EvoHub can read yours.
  • A password must be at least 8 characters. Administrators can raise the minimum for their organization (see Login policies).
  • You can sign in with Google or GitHub instead of a password, and connect or disconnect those accounts under My Account → Authentication → Connected accounts.

Sign-in protection

  • Account lock. After 5 wrong passwords, the account is locked for 15 minutes, even for the right password. This makes guessing passwords slow and expensive.
  • Bot protection. The sign-in, sign-up, password-reset and verification-email forms are protected by Cloudflare Turnstile, which tells people apart from automated abuse.
  • Two-factor authentication. Add a time-based one-time code from an authenticator app to every sign-in. See Two-factor authentication.
  • Short-lived links. Password reset links are valid for 15 minutes and email verification links for 24 hours.

Sessions

  • After you sign in, the console holds a short-lived, signed access token that is renewed in the background while you use EvoHub. Sessions are stored on EvoHub's servers and can be ended at any time.
  • A session ends after a period of inactivity. The default is 7 days; administrators can change it (see Login policies).
  • My Account → Active Sessions lists every device signed in to your account, with its IP address, when it was last seen and when it signed in. Select Revoke to sign a device out. See Two-factor authentication.
  • Signing out ends the session. Deleting your account ends all of them.

Login policies

Administrators can set security requirements for everyone in an organization under Organization → Login Policies:

Setting What it does
Require MFA Every member must set up two-factor authentication before they can enter the organization.
Session Timeout Hours of inactivity after which members are signed out. Default 168 (7 days).
Minimum Password Length Passwords shorter than this are rejected when members set or change a password.

Select Save Policies to apply them.

Tenant isolation

Every organization's data is kept apart from every other organization's.

  • Every request is tied to exactly one organization by the signed token or API key it carries. EvoHub's servers decide which organization a request belongs to; a client cannot choose it.
  • Every read and write of organization data is filtered by that organization. An ID that belongs to another organization simply is not found.
  • Inside an organization, work can be scoped to a team. Something that belongs to a team you cannot see is reported as not found, so its existence is not revealed.

Authorization on the server

  • Every action is checked against the caller's organization roles on EvoHub's servers. The console hides what you cannot do, but the API enforces it independently. See Roles and permissions.
  • You can never grant a role, or give an API key, a permission you do not hold yourself.
  • A refused action returns 403. It never signs you out.

API keys

  • An API key is shown once, when it is created. EvoHub stores only a SHA-256 hash of it, so a key cannot be recovered from EvoHub, even by EvoHub.
  • A key has exactly the scopes it was given, can expire, and can be revoked instantly. A key never counts as an administrator.
  • A personal key loses whatever its owner loses, and stops working when its owner leaves the organization or deletes their account.
  • Every key starts with evohub_, so secret scanners can recognize a leaked key.

See API keys and scopes.

Payment details

Card details are entered into a form provided by Stripe, EvoHub's payment processor. Card numbers go directly to Stripe and never reach EvoHub's servers.

Audit logs

Organization → Audit Logs records administrative and configuration actions, such as creating and revoking API keys and changes to members, roles and settings, across the organization. It is visible to people with an audit-log read permission. The default Admin, Member and Viewer roles all include it; build custom roles without it if you want to restrict who reads the log. Audit logs are kept for 1 year.

Report a security problem

If you believe your account has been compromised, or you have found a security issue in EvoHub, email info@evosync.io right away.

Zuletzt aktualisiert am