Security & Trust

Understand Clearplane's exposure, network, service-identity, and container-runtime boundaries.

Clearplane narrows public exposure, separates control-plane and application traffic, and authenticates communication between its own services. These boundaries reduce the impact of a compromised component; they do not replace host, container-runtime, application, or operational security.

  • Exposure and network boundaries explains why Edge is the only public Clearplane container and how the three networks are wired.
  • Internal service trust explains exact-identity mTLS between Edge, Core, UI, and ContainerProxy.
  • Container runtime isolation explains why only ContainerProxy receives the runtime socket.
  • Unsigned local rules explains how custom rules reach Edge over Core's authenticated channel.
  • Review WAF detections explains how to read what the WAF matched, what Edge redacts before recording a detection, and how to narrow a noisy rule before enabling Prevention.
  • Use WAF exclusion rulesets explains how routes opt into an application's exclusions without per-route tuning.
  • WAF inspected traffic covers WebSocket messages, binary gRPC streams and bodies above the inspection limit.
  • WAF rulesets explains WAF policies, signed releases, stages, opt-outs, and rollback.
  • WAF scoring and paranoia levels explains combined thresholds, independent ruleset thresholds, and detection-only scores.
  • Bot challenges explains what a challenge clearance binds and how rotating its key invalidates clearances.
  • Hardening checklist turns the model into practical operator checks without treating one control as complete protection.
  • WAF protection coverage reports measured detection and false-positive rates for the tested category rulesets.
  • WAF rule language explains the format, targets, operators, detectors and integrity tests.
  • Third-party notices lists the third-party work Clearplane includes and reproduces its licence text.

For suspected vulnerabilities in Clearplane itself, use the private security reporting channel.