| Version | Supported |
|---|---|
| 0.4.x | ✅ |
| 0.3.x | ✅ |
| < 0.3.0 | ❌ |
DOMINUS Community is a self-hosted tool with no multi-tenancy, no user authentication, and no network-exposed attack surface beyond the REST API bound to localhost by default. DOMINUS Cloud is a managed multi-tenant service with authenticated access.
If you discover a security issue in either edition:
- Do not open a public GitHub issue.
- Send details to the repository owner via a [private vulnerability report] on GitHub.
- You should receive a response within 7 days.
DOMINUS follows these security principles:
- All API keys and credentials are read from environment variables (
.envfile, gitignored). - The
.env.examplefile documents every variable without real values. - No tokens, keys, or passwords are hardcoded or committed.
- Every SQL query uses parameterised statements via
better-sqlite3.prepare()or parameterised PostgreSQL queries. - No string concatenation or template literals are used in SQL queries.
- Domain names are validated against RFC-1123 rules before any provider call.
- CSV imports are validated for schema compliance before processing.
- File paths are resolved safely (no directory traversal).
- All API inputs are validated with Zod schemas.
- The Express API binds to
127.0.0.1by default (localhost only). - In Docker,
HOST=0.0.0.0is required for container ingress — access should be restricted by reverse proxy or firewall. - All standard HTTP security headers are set (
X-Content-Type-Options,X-Frame-Options,X-XSS-Protection,Strict-Transport-Security).
- Static API key from environment variable — single-key, single-user.
- No session management, password hashing, or user registration.
- API key should be treated as a secret and rotated periodically.
- JWT-based authentication with short-lived access tokens (15 minutes) and refresh tokens (7 days).
- Auth0/Clerk managed identity provider for OAuth, password hashing, and brute-force protection.
- API keys for CLI access are hashed with bcrypt (never stored in plaintext).
- Row-Level Security on PostgreSQL enforces tenant isolation at the database level.
- Dependencies are scanned for known vulnerabilities before addition.
- Dependabot is configured for weekly npm updates.
- Only well-maintained, widely-used libraries are selected.
- Community edition: SQLite WAL mode for safe concurrent access. The database
file is stored in a gitignored
data/directory. Automatic backups viadominus maintenance backup(VACUUM INTO). - DOMINUS Cloud: Managed PostgreSQL with automated daily backups, point-in-time recovery, and encrypted storage at rest.
- Tenant isolation is enforced at three layers:
- Application: all queries filter by
tenant_idcolumn - Database: PostgreSQL Row-Level Security policies on every table
- Network: tenants are isolated at the application layer (no direct database access)
- Application: all queries filter by
- Cross-tenant data access is validated in CI with integration tests.