Fail closed at every artifact boundary — Potion

Security

Fail closed at every artifact boundary

Potion treats uploaded archives, redirects, remote endpoints, premium objects, credentials, and logs as separate trust boundaries.

Responsible disclosure

Report vulnerabilities privately to security@potion.sh with a minimal, safe reproduction.

Private source

Release and premium archives remain private and immutable; signed access is short-lived and authorized.

Secret-free operations

Tokens, passwords, payment data, keys, and raw MCP secrets are excluded from responses, logs, and audits.