Connect · Security
How Connect keeps logins and limits safe
The short version: the agent never holds the keys, every step is checked in code against limits a person approved, and the receipt comes from the site, not the agent.
Logins
- Sealed on arrival. Passwords and authenticator secrets are encrypted with a fresh data key from AWS KMS, bound to the owner and the login. Our API cannot read them back, and neither can you.
- Opened only inside the session. The session worker unseals a login inside an isolated browser opened for that session alone, types it, and clears the fields. Authenticator codes are computed at the moment the site asks.
- Never in an observation. Password fields, one-time-code fields and anything marked as a login are left out of what the agent sees. We never log a secret, a page body or a screenshot that could hold one.
- Delegate logins, not owners' passwords. For state portals the business adds a separate login for you, which it can remove at any time.
Limits
- Signed licenses. Every session runs under an Ed25519-signed license naming one site, the operations, a spending cap, blocked actions, a step cap and a time window.
- Checked in code before each step. We read the real button label and the real total from the page, not what the agent claims. Text on a page, including planted instructions, cannot change a rule.
- No wandering. The browser only goes to the start page or links on the current page, only on the licensed site.
- A person says yes before it commits. With
before_submit, filing and paying wait for an explicit approval. Silence counts as no. - Kill switch. A revoked license refuses new sessions, and a running session stops before its next step.
Receipts
A receipt records the site's own confirmation number, the facts on the confirmation page, a hash of that page, and every blocked step with its reason. It never carries raw error text. A session that may have submitted without a confirmation ends outcome_unknown and is never retried automatically.
Calls to your servers
Step calls and webhooks are signed with HMAC-SHA256 and a timestamp. We only call https URLs on port 443 that resolve to public addresses, check again on every call, and never follow redirects.
What we do not do
- We do not solve CAPTCHAs. Solving is switched off in every browser we run: a licensed agent identifies itself instead of evading bot checks.
- We do not record or log browser sessions on real accounts.
- We do not store API keys, only their SHA-256 hash.
Report a problem
Write to hello@computeruse.si. We answer security reports first.
Docs: Quickstart · State tax portals · API reference · Security