Skip to content

docs: audit security, integrations and deployment pages - #127

Merged
pavancharak merged 1 commit into
mainfrom
docs/audit-integrations-deployment
Oct 2, 2026
Merged

pavancharak merged 1 commit into
mainfrom
docs/audit-integrations-deployment

Conversation

@pavancharak

Copy link
Copy Markdown
Owner

What

Page by page audit, batch 9: security, integrations and deployment, checked against the code and docs/CLAIMS.md on 2026-10-02.

Real errors fixed:

  • Security overview and limitations: both said independent instances can each accept the same authorization once. Parmana's own server shares its authorization and approval nonce stores in Postgres and fails closed without them; CLAIMS 3.2, which the overview mirrors, already said so. Both also said any authenticated caller can call any route; every governance route refuses a key not provisioned as a human. A new connector no longer always needs code (external connectors). The latency gap now cites G-84 (24 to 32 s in production), and connector calls do have timeouts.
  • Connector development guide: said adding a connector means editing two files. Slack, the most recent, touches sixteen files across four packages, plus the capability binding (which refuses to start when unbound), a policy with its approval, and two architecture tests. Now listed as a table.

Checked with no change needed: the production runbook (every script and flag exists), running from source (demo key hash matches), HubSpot (approval paths match the policies). The agent spec, deploy spec, quickstart, Playground and the nine self hosted pages were written in the last two weeks; they pass the new sample tests (#126) and a sweep for the stale patterns found so far.

🤖 Generated with Claude Code

Checked on 2026-10-02 against the code and docs/CLAIMS.md.

- Security overview and limitations: the replay caveat said instances
  each accept an authorization once; Parmana's own server shares its
  nonce stores in Postgres (CLAIMS 3.2 already said so). "Any caller can
  call any route" is no longer true: governance routes refuse a non human
  key. A new connector needs no code as an external connector. The
  latency gap cites G-84, and connector calls do have timeouts.
- Connector development guide: said adding a connector means editing
  two files; Slack touches sixteen across four packages plus the policy
  binding, a policy and two architecture tests, now listed.
- Production runbook, local, HubSpot and the recent agent, quickstart,
  Playground and self hosted pages checked; no change needed.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@vercel

vercel Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
parmana-api-real Ready Ready Preview Oct 2, 2026 11:32am UTC
parmana-sandbox Ready Ready Preview Oct 2, 2026 11:32am UTC

@mintlify

mintlify Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
parmanasystems 🟢 Ready View Preview Oct 2, 2026, 11:32 AM

💡 Tip: Enable Automations to automatically generate PRs for you.

This branch was successfully deployed

3 active deployments
Preview – parmana-api-real — e9a9a9d1 Deployed Oct 2, 2026 by vercel[bot]
Preview – parmana-sandbox — e9a9a9d1 Deployed Oct 2, 2026 by vercel[bot]
staging - docs/site — e9a9a9d1 Deployed Oct 2, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant