Security overview
How Fah Swe RTC protects your credentials, users and media.
Overview
Security is layered: your App Secret never leaves your server, apps receive short-lived scoped grants, and every media packet is authenticated and encrypted.
What the platform does
- Media: signed grants, ECDH P-256 key agreement, AES-256-GCM encryption and replay protection
- Tokens: lifetime capped at one hour (10 minutes by default); grants can be revoked
- Token API refuses browser calls, so a leaked secret in a web page fails immediately
- Optional IP allowlists and publish/subscribe scopes per credential
- Console: CSRF protection, exact-origin CORS, role-based access, tenant isolation, audit log
- Transport: HTTPS/TLS everywhere; TURN over TLS for restrictive networks
What you should do
- Keep App Secrets in your server's secret store, never in apps or repositories
- Issue the smallest role and stream set each user needs
- Rotate credentials if you suspect exposure, and revoke grants for removed users
Source references
apps/local-site/lib/product-status.ts
Was this page helpful?