Security Built for Paranoia, Not Convenience
Autvy enforces Ed25519 digital signatures, monotonic replay protection windows, and zero inbound listening ports. Here is our complete security specification.
SPEC 01 // SIGNATURE VERIFICATION
Ed25519 Instruction Signing
The Autvy worker accepts instructions exclusively from the Autvy Supervisor. Every dispatched payload is cryptographically signed using Curve25519 high-speed Ed25519 public-key signatures.
The public key is hardcoded directly into the compiled host binary. Any payload with an invalid or tampered signature is discarded immediately without execution.
SPEC 02 // ANTI-REPLAY
60-Second Sliding Replay Windows
To prevent network adversaries from intercepting valid signed commands and replaying them later, every command contains a monotonic sequence nonce and a microsecond timestamp.
Instructions with a timestamp drifting by more than ±60 seconds from the server hardware clock are rejected. A local sliding bloom filter deduplicates nonces.
- • Monotonic incrementing sequence counters per site registration
- • Sliding 10,000-element counting bloom filter resident in worker RAM
- • Strict clock-drift ceiling: max 60,000 milliseconds tolerance
SPEC 03 // AIR-GAP RESILIENCE
Fail-Safe Degraded Posture
What happens if Autvy's cloud supervisor infrastructure goes offline? Your WordPress site continues functioning at 100% speed with zero interruption.
Autvy runs purely as an observer and local reactor. If the supervisor API fails to respond, the local mu-plugin defaults to safe non-blocking bypass mode.
Autvy introduces zero external HTTP dependencies into visitor page requests. If Autvy servers are down, your website visitors never notice a single millisecond of latency difference.
Responsible Disclosure
Found a security flaw or vulnerability?
Report to [email protected] with safe harbor protections.