Security Architecture & System Hardening
BotDigit is engineered from the ground up on a zero-trust security model. We maintain zero public open ports, run memory-safe compiled Rust services, and physically air-gap financial databases.
Core Infrastructure Safeguards
Zero Public Open Ports
All production traffic routes through outbound-only Cloudflare Zero-Trust tunnels (`cloudflared`). The host infrastructure has no listening ingress ports exposed to the public internet, eliminating network-level port scanning and DDoS attacks.
Compiled Rust Microservices
Core backend services (`api-gateway`, `platform-service`, `wallet-service`) are compiled with Rust, providing memory safety, zero-cost abstractions, and immunity to memory corruption exploits like buffer overflows.
Database Air-Gapping & Segregation
Financial balances and escrow states reside in an isolated `wallet_db` schema completely distinct from the general `platform_db`. AI agents and public MCP gateways possess zero direct database connection strings.
Multi-Tenant Tenant Isolation
Workspaces are cryptographically sandboxed. Every internal query enforces strict caller token ownership checks, preventing cross-tenant data leaks even in the event of prompt injection.