# Witina AI — Security > Device credentials are never stored in Witina's cloud. The gateway only dials out. > Discovery is passive by default. Every configuration change is approved, snapshotted, > verified and reversible. Witina is early and pre-audit, with no third-party > certification yet — and says so. Source: https://witinaai.com/ai/security.md Part of the Witina AI machine-readable corpus — index: https://witinaai.com/llms.txt Last updated: 2026-09-09 Human version: https://witinaai.com/security ## The claim, and how to check it A platform that can read your topology and push configuration to live gear has to be trustworthy in its bones, not just at the login screen. Witina's position is that the strongest security claim available to an early company is not a badge but **a copy you can inspect**: the self-hosted edition is the same code, runs entirely on your own hardware with no account and no credentials sent anywhere, and lets you watch exactly what it does and does not transmit. ## Credentials **Witina does not store your device credentials.** When you add one in the console it is relayed over TLS to a gateway on your own network and kept encrypted there, on infrastructure you run. | Where | What exists there | |---|---| | In Witina's cloud | **Device passwords are not stored here.** | | In transit | Relayed to your gateway over TLS, held in memory, then written only to the gateway — encrypted. | | At rest | On a gateway you run. Self-host and even the transit stays on your LAN. | Encryption at rest on the gateway uses a wrapped-key (keyslot) model with three policies you choose between per gateway: **TPM-sealed**, **SaaS-assisted** (key split between gateway and cloud, so neither a stolen gateway nor a cloud breach decrypts alone), or a **local key file**. De-authorizing a SaaS-assisted gateway withholds the cloud's share, making its data cryptographically unrecoverable — a crypto-shred that does not require recovering the hardware. Full detail: https://witinaai.com/ai/architecture.md ## Network exposure - **No inbound ports.** The gateway makes an outbound TLS connection and everything rides over it. You never expose a management plane to the internet. - The gateway proves its identity with a signed token; it is provisioned once with a pairing token and renews itself. ## Gateway privilege - Runs as an **unprivileged user**, not root, with a handful of narrow Linux capabilities — enough to sniff packets for discovery and serve firmware on one port. A compromise of the gateway process is not a root shell on your router. - Reboots and image upgrades go through a separate, API-mediated path. - **Scoped credentials**: you decide which credentials may touch which devices. Access is an auditable mapping, not a global admin blob. ## Discovery is quiet by default Bringing a network online should not set off your own alarms. Discovery starts **passive** — listening to DHCP, LLDP/CDP and mDNS rather than scanning. Active probing and auto-connect are **opt-in** decisions you make per network. ## Change safety Configuration changes are not anonymous, irreversible edits. Each one can be routed through approvals, **snapshots the device's current state before touching anything**, verifies the result, and can be **rolled back** to the snapshot — with a complete audit log of who did what, when and why. ## Tenancy and identity - **Multi-tenant isolation** via an Organization / Division / Region hierarchy that scopes every record. Access is checked **per request** against the scope you are acting in. - **Bring your own identity**: OIDC / OAuth (Authorization Code + PKCE), configured globally or per organization. - **Activity logging** records user actions, separately from device audits. ## AI agent access Witina exposes an MCP server so external AI agents can read network state and draft changes. The authorization model is deliberately conservative: - An agent authenticates via **OAuth 2.1** — PKCE S256 mandatory, exact redirect matching, opaque tokens stored hashed, short-lived access tokens, rotating refresh tokens with reuse detection, and RFC 8707 audience binding so a token minted for another resource is rejected. - An agent's effective permissions are its granted role **intersected with the current permissions of the human who authorized it**, in one pinned context — recomputed on every request, not baked into the token. - Four independent conditions drop it to zero permissions: revocation, the authorizing user's credential change (a password reset kills every agent they authorized), that user losing organization access, or a context mismatch. - Of nine tools, **only two can write, and both write only into a draft** change management that a human must run. Full model and complete tool schemas: https://witinaai.com/ai/mcp.md and https://witinaai.com/mcp/tools.json ## What Witina does not claim Witina AI is an early, pre-audit company. **There is no third-party security certification to point at yet** — no SOC 2 report, no ISO certificate. The marketing site states this plainly rather than implying otherwise. What exists instead is an architecture that keeps secrets on the customer's side by construction, and a self-hostable copy that can be inspected end to end. Security questions: hello@witinaai.com ## Related - Architecture: https://witinaai.com/ai/architecture.md - Privacy policy: https://witinaai.com/privacy - Terms of service: https://witinaai.com/terms