Skip to content

Security model

HLA-Compass evaluates access using the credential, organization, role, resource policy, and operation being requested. Authentication alone does not grant access to every catalog, module, result, or administrative action. This guide describes the platform contract; use the target environment's release metadata and API contract to identify the deployed version. It is not a certification of every deployment or third-party client.

Choose the right credential

Credential Use it for Keep in mind
Browser or CLI bearer session Interactive work and permitted administration Membership, role, session policy, and MFA requirements apply.
Connected-app OAuth grant A chat app using governed data and tools Access stays in the organization approved at consent and within the user's permitted actions.
Personal API key Scripts, SDK integrations, and CI Key permissions/scopes and current owner membership apply; administrator authority is not inherited.
Module-run credential The capabilities admitted for one execution It is tied to that run and its declared data/storage access.
Presigned URL A specific object operation until expiry Anyone holding it may be able to perform the signed operation. Treat it as a secret.

Follow API and authentication to create, store, check, rotate, or revoke a key. Use separate credentials for separate integrations. Read and write are independent permissions; selecting a mutation scope does not grant access to every resource in that area.

MFA, sign-in, and account changes

MFA protects interactive sign-in and privileged operations. If the platform returns MFA_REQUIRED, complete its supported browser/challenge flow and retry only when the operation is safe to repeat. Never save a one-time code, recovery code, bearer token, or refresh token in a prompt, source file, or notebook.

An API key does not carry MFA proof and cannot replace an administrator's interactive session. Its recorded grants are limited by current owner membership and role, with a developer-role ceiling. Removing a membership or reducing a role can prevent requests that used to succeed.

Revocation has operational limits. Cached API-key authorization can remain valid briefly; verify rejection after revoking an exposed key. Disconnecting a chat app stops further authorized access, but does not remove content already sent to that app. Revoking a key, session, or connection does not undo completed work or erase downloaded files. Review the receiving application's retention and sharing settings before sending it scientific data.

Protect data and reproducibility

  • Use governed discovery and data operations. Do not construct another organization's bucket name or object path to bypass access checks.
  • Record immutable Catalog Version and Dataset Version IDs, module versions, pipeline revisions, run IDs, and checksums with an analysis. A mutable “latest” reference alone is not sufficient to reproduce it.
  • Use run-scoped input and result access from the SDK. A module's credentials must not be copied into another process or reused as a personal key.
  • Share notebooks through the platform's supported sharing action. Underlying referenced data is reauthorized for the reader; notebook sharing does not grant source-data access. Arbitrary pasted text and external outputs are not automatically tracked, so review manual content before attesting to a share.
  • Review a costed execution plan and confirm the intended inputs, compute, destination, and permitted action before starting consequential work. Follow the operation's documented confirmation contract.

Keep bearer tokens, API keys, presigned URLs, temporary storage credentials, and database credentials out of source control, manifests, notebooks, chat prompts, logs, and generated artifacts. Use a secret manager for persistent credentials and pass only the capabilities the integration needs.

For SDK and module authors

Use the SDK's supported authentication and storage paths. Treat the selected environment and organization as explicit inputs, and validate resource/version identifiers received from an external caller. Pin and scan dependencies and container artifacts; dependency scanning does not prove that a module is safe.

Keep module UI and runtime trust boundaries distinct. A same-page module UI is trusted publisher code running in the user's browser; host capabilities are permission-checked, but the UI is not a separate browser sandbox. Do not put secrets into its props or bundle. Backend execution must use the supported runtime and admitted capabilities, rather than ambient administrative credentials.

Reporting a security issue

Do not place vulnerability details, credentials, or private scientific data in a public issue or ordinary chat. Contact Alithea Bio through the company website and request a private security-reporting channel. Share the affected environment, route, and a minimal reproduction without active secrets or another user's data.

If you exposed a credential, revoke it promptly. Preserve relevant request IDs and timestamps for investigation; do not delete scientific data as a way to remove evidence of an access problem.