BiztonságSecurity
Egy rendszer, ami idegen kódot ír és futtat, csak akkor vállalható, ha a határai világosak. Ez az oldal leírja, mi hol fut, mit tárolunk, és mit nem – a kódban ténylegesen megvalósított védelmekkel, nem ígéretekkel.
A system that writes and runs generated code is only acceptable if its boundaries are clear. This page describes what runs where, what we store and what we don't – with the protections actually implemented in the code, not promises.
Saját kulcs (BYOK)Bring your own key
- A modellhívások a te API-kulcsodon mennek; a szolgáltató neked számláz. Ha nincs meg a csapathoz szükséges kulcs, a futás el sem indul – a szerver saját kulcsára soha nem esik vissza.
- A kulcsokat XChaCha20-Poly1305 titkosítással tároljuk. A mesterkulcs külön fájlban van, nem az adatbázisban: az adatbázis kiszivárgása magában nem adja ki a kulcsokat.
- A titkosítás a fiókodhoz és a kulcs nevéhez kötött – egy titkosított kulcs nem másolható át egy másik fiókba vagy kulcsnév alá.
- A felület a kulcsot soha nem adja vissza, csak az utolsó négy karakterét mutatja.
- A kulcs a gazdagépen marad: a modellhívásokat a szerver végzi, a futtató konténerbe a kulcs soha nem kerül.
- Model calls go on your API key; the provider bills you. If a key the team needs is missing, the run does not start – it never falls back to a server key.
- Keys are stored with XChaCha20-Poly1305 encryption. The master key lives in a separate file, not in the database: a leaked database alone does not reveal the keys.
- The encryption is bound to your account and the key name – an encrypted key cannot be copied into another account or under another key name.
- The interface never returns the key, it only shows its last four characters.
- The key stays on the host: the server makes the model calls, and the key never enters the run container.
Futás konténerben, hálózat nélkülRuns in a container, without network
A csapat által írt kód nem a szerveren fut. Minden futás saját, hálózat nélküli Docker-konténert kap, és abban csak a kapuk parancsai – fordítás, tesztek, build – futnak, a projekted mappájával. A konténer nem éri el az internetet, a szerver többi részét és a többi felhasználó adatait. Csomagot futás közben telepíteni nem lehet; a projekt függőségeinek a futtató képben kell lenniük.
Code written by the team does not run on the server itself. Every run gets its own network-less Docker container, where only the gate commands – compile, tests, build – run, against your project folder. The container cannot reach the internet, the rest of the server or other users' data. Packages cannot be installed during a run; the project's dependencies must already be in the runtime image.
FiókokAccounts
- Regisztrálni csak meghívókóddal lehet; a kód egyszer használható, és csak a hash-ét tároljuk.
- A jelszót nem tároljuk, csak az Argon2 hash-ét. Legalább 10 karakter.
- Belépési korlát: e-mail címenként 10 sikertelen próbálkozás 10 percen belül. Ismeretlen e-mail címnél is lefut egy valódi jelszó-ellenőrzés, hogy a válaszidő ne árulja el, létezik-e a fiók.
- A munkamenet egyetlen HttpOnly, SameSite=Strict süti (élesben Secure), 14 napig érvényes; az adatbázisban csak a token hash-e van.
- Egy másik felhasználó futása, projektje vagy kulcsa a te szemszögedből nem létezik: minden ilyen kérésre 404 a válasz.
- Registration is invite-only; a code works once, and we only store its hash.
- We don't store your password, only its Argon2 hash. Minimum 10 characters.
- Login limit: 10 failed attempts per email address within 10 minutes. For unknown email addresses a real password check still runs, so the response time does not reveal whether an account exists.
- The session is a single HttpOnly, SameSite=Strict cookie (Secure in production), valid for 14 days; the database only holds the token's hash.
- Another user's runs, projects or keys do not exist from your point of view: every such request returns 404.
A felületThe web interface
- Szigorú CSP: csak a saját szerverről tölthető szkript és stílus, beágyazott szkript nincs. Ha egy projektfájl tartalma valahogy HTML-ként kerülne az oldalba, a benne lévő szkript akkor sem futna le. Egy automata teszt minden oldalt ellenőriz erre.
- CSRF-védelem: minden módosító kérés egy saját fejlécet követel, amit egy idegen oldal a böngészőből nem tud elküldeni.
- X-Frame-Options: DENY, nosniff, no-referrer. A betűk helyben vannak – külső kérés, követés, analitika, reklám nincs.
- Feltöltés: a zip-feltöltés védett a „zip slip” (mappán kívülre írás) és a „zip-bomba” (hatalmas kicsomagolt méret) ellen; felhasználónként 500 MB tárhely.
- Strict CSP: scripts and styles only from our own server, no inline scripts. If the content of a project file somehow ended up in the page as HTML, the script in it still would not run. An automated test checks every page for this.
- CSRF protection: every modifying request requires a custom header that a foreign site cannot send from the browser.
- X-Frame-Options: DENY, nosniff, no-referrer. Fonts are served locally – no external requests, tracking, analytics or ads.
- Uploads: zip uploads are protected against “zip slip” (writing outside the folder) and “zip bombs” (huge unpacked size); 500 MB storage per user.
Helyi Claude (frst-bridge)Local Claude (frst-bridge)
Ha a saját gépeden futó Claude Code-ot csapattagnak veszed, a gépeden futó frst-bridge kifelé kapcsolódik a szerverhez, és a feladatokat onnan kéri le – a gépedre nem kell bejövő kapcsolatot nyitni. A Claude eszközök nélkül, egyetlen körben, üres ideiglenes mappában fut: nem olvas és nem ír fájlt, nem futtat parancsot, csak szöveget ad vissza. A híd tokenjéből csak a hash-t tároljuk, és bármikor visszavonhatod. A saját Claude-előfizetésen keresztül más felhasználók kéréseit kiszolgálni nem szabad.
If you add the Claude Code running on your own computer as a team member, the frst-bridge on your machine connects out to the server and fetches the tasks from there – no inbound connection to your computer is needed. Claude runs without tools, in a single turn, in an empty temporary folder: it does not read or write files or run commands, it only returns text. We only store the hash of the bridge token, and you can revoke it at any time. Serving other users' requests through your personal Claude subscription is not allowed.
Béta: amit most nem ígérünkBeta: what we don't promise yet
A szerver egy bérelt virtuális szerveren fut a Rackforest budapesti adatközpontjában; a titkosított kapcsolat a saját szerverünkön végződik. Naponta mentünk, de rendelkezésre állást és visszaállítást nem vállalunk: a fontos projektjeidet töltsd le zip-ként. A modellszolgáltatóknak a projekted kódja és a célod a promptokban eljut – ne tegyél bele személyes adatot vagy titkot. A részleteket az adatkezelési tájékoztató írja le.
The server runs on a rented virtual server in Rackforest's data centre in Budapest; the encrypted connection terminates on our own server. We back up daily, but we don't promise availability or restores: download your important projects as zip files. Your project's code and your goal reach the model providers inside the prompts – don't put personal data or secrets in them. The details are in the privacy notice.
Biztonsági hibát találtál? Írj a contact@frstrun.eu címre. Kérjük, ne használd ki, és ne férj hozzá más felhasználók adataihoz – javítjuk, és megköszönjük.
Found a security issue? Write to contact@frstrun.eu. Please don't exploit it or access other users' data – we'll fix it and thank you.