Noryun

Security

Designed around least privilege.

Noryun separates platform authorization, workspace access, approval, execution, and audit responsibilities so that one connection does not become unrestricted access.

Official authorization

Supported accounts connect through the official OAuth or business authorization flow provided by the relevant platform. Noryun does not request the password a user uses on that platform.

Access control

Existing Noryun infrastructure enforces organization and workspace boundaries, role-based permissions, request identifiers, and audit events. The isolated reviewer workspace is protected by a dedicated role and workspace-mode check. Temporary credentials and platform-specific access remain disabled until their tests and reviewer materials are approved.

Credential protection

Secrets are not committed to source control or exposed in browser bundles. Production platform credentials will be supplied through protected secret files or a secret manager. Social token key versioning and rotation are part of the next implementation phase and are not yet claimed as production-ready.

External-write controls

External writes and AI auto-publishing are disabled by default. The required social publishing and comment-reply gates will preserve human approval and prohibit self-approval unless a separately audited emergency process is authorized.

Logging and incident response

Application logging masks common credential fields. A suspected credential exposure requires disabling external writes, stopping the affected queue, revoking affected authorization, rotating secrets, and auditing the affected time window.

Report a concern

Email security@noryun.com. Do not submit passwords, one-time codes, OAuth tokens, private keys, or identity documents through an ordinary email message.