Security and data
How Interopt handles your secrets, source, and targets.
Data location
Interopt runs on Google Cloud in the Netherlands. Your workspace data is stored there.
What a scan may do
- Every scan requires an authorization confirmation for the target, enforced on the server rather than only in the form.
- Irreversible actions are off by default and have to be turned on per scan.
- A scan freezes its configuration when it starts, so a later edit cannot widen a run already in progress.
- Scanner traffic comes from published outbound addresses, so you can tell it apart from everything else hitting the target.
See Safety limits for the full controls.
Secrets
Secrets are encrypted before they are stored:
- Auth profiles: headers and cookies used for authenticated testing.
- Env profiles: environment variables for white-box runtimes.
- OAuth tokens for connected code hosts and issue trackers.
- Webhook URLs for alert channels.
Scan credentials are read only by the scan runner.
Source code
Interopt reads only the repositories you select when you connect a code host. Disconnecting revokes the installation or OAuth grant on the provider's side.
Context documents
Specs, diagrams, and notes attached to a scan are stored privately and given read-only to that scan's agents. Up to five per scan, 10 MB each and 25 MB in total.
API tokens
A token is shown in full once, at creation. After that, Interopt keeps only its last four characters. Tokens are scoped, revocable, and can be rotated with an overlap window.
MCP server
Apps connected over the MCP server sign in through Interopt and act as the member who approved them, in one workspace, with the permissions that member allowed. Each request is checked against the member's current role and the workspace's two-factor requirement. Owners and admins see every connection on Settings → MCP and can cut any of them off; the app's next request fails.
Access
- Four roles: owner, admin, member, and read-only.
- Admins choose the allowed sign-in methods and can require two-factor with TOTP or passkeys. See Authentication.
- Every finding keeps an activity trail of status changes and assignments.
Deleting a workspace
Only the owner can delete a workspace, by typing its name to confirm. Assets, findings, and scans are removed and members lose access immediately. There is no export and no restore.
