Security
Sensitive context deserves visible safeguards.
RingMyHuman is designed to limit access to human-help context and protect credentials throughout the request lifecycle.
Protection measures
Production infrastructure uses TLS, AWS-managed encryption at rest, scoped IAM roles, private object storage, hashed MCP credentials, replay-protected webhooks, and redaction-aware logging.
- Raw MCP access tokens are shown only when created and are not stored for later retrieval.
- Signed callback payloads include a timestamp and idempotency key.
- Call jobs and callbacks use durable queues with dead-letter handling.
- Access to account resources is scoped to the authenticated owner.
Important limitation
RingMyHuman is a cooperative human-in-the-loop service. It is not an enforceable approval boundary. A protected downstream system must independently verify authorization before carrying out sensitive or irreversible actions.
Report a concern
Report suspected security issues privately to info@email.famplified.com. Please do not include access tokens, full transcripts, or other unnecessary sensitive data.