Skip to content

Security at Localport.

What Localport can see, what it records, who holds the keys and how access is removed.

Built on security and privacy.

The summary, then the detail a security review needs.

Traffic content is never logged
Only connection metadata is recorded.
Keys stay on the device
Private keys never leave the machine that holds them.
Access ends immediately
Removing access closes open connections.
Open-source agent
The code that runs on your machines is public.

What Localport can see

It depends on the kind of connection.

TLS tunnels
Traffic stays encrypted all the way to your service. Localport holds no key for it and cannot decrypt it.
TCP tunnels
Bytes are forwarded as they arrive and are not inspected. A protocol that encrypts itself, such as SSH, stays encrypted.
HTTP and HTTPS tunnels
Localport serves HTTPS with its own certificate. A request is decrypted in memory to apply the rules set on the tunnel, then forwarded to the agent over an encrypted connection. Nothing is written to disk.
Remote Access
The caller's certificate is verified, then traffic is forwarded to the device over an encrypted connection. Nothing is written to disk.
Agent connection
Every connection between the agent and Localport uses TLS 1.3.

What is recorded

Metadata about connections only.

Connection metadata
Connection counts, bytes transferred, request counts, session start and end times, region, agent version and disconnect reasons. Used for billing, operations and abuse handling.
Access log
For Remote Access: the identity that connected, the device and port, the source address, the time, the outcome, the duration and the traffic volume. Readable by the team's admins.
Audit log
Administrative changes in a team: who made the change, what changed, when and from which address. The address is removed from an entry after 90 days.
Never recorded
Request paths, headers, bodies and payloads.

Keys and credentials

Every credential is a certificate, and no private key is ever sent to Localport.

Private keys
A key is generated where it will be used, by the agent or in the browser. Only a signing request is sent. Localport has no way to receive a private key.
People
A member signs in with localport login and approves the request in the browser. The certificate lasts hours and is not renewed.
Machines
A machine redeems a single-use setup key, then renews its own certificate. No long-lived secret stays on the machine.
CI pipelines
A pipeline proves its identity with an OIDC token from its own platform. No secret is stored. The certificate lasts 15 minutes and is held in memory.
Bring your own CA
An existing certificate authority is registered for verification only, with its revocation list. Its private key is never uploaded.
Tunnel tokens
Stored as a SHA-256 hash, with an AES-256-GCM encrypted copy for display in the dashboard. Rotating a token stops the old one immediately.

How access is decided

Nothing is reachable until it is allowed.

Private by default
A fleet device accepts no connection without a certificate and a grant. A certificate with no grant reaches nothing.
Explicit grants
Access is granted to a member, a role or a machine, for one device, a group of devices or the whole fleet. Nothing is allowed implicitly.
Tunnel protection
IP allowlist, basic auth, header authentication and webhook signature verification. Each is checked on every request.
Source restriction
A tunnel can be limited to agents connecting from listed addresses, so a leaked token alone cannot bring it online.
Dashboard sign-in
The dashboard supports passkeys, and a team can require them for its members.

How access is removed

Each of these takes effect on connections that are already open.

Revoke a certificate
Connections using that certificate close.
Remove or narrow a grant
Connections the grant covered close.
Remove a device
The device is disconnected and its agent stops reconnecting. With auto-join off, it cannot join again.
Remove a certificate authority
Connections that relied on it close.
Remove a team member
Their access ends on every fleet and their connections close.

The agent

The one piece of Localport installed on your machines.

Open source
The agent is published on GitHub under the Apache 2.0 licence.
Outbound only
The agent connects out on port 443. No inbound port is opened on the machine or its network.
TLS 1.3
Required on every connection the agent makes. No setting lowers it.
Signed releases
Release checksums are signed, and the installer verifies them before it installs.
Key files
The agent refuses a private key file that other users on the machine can read.
No personal data
A stored credential holds a username, a team id and a team name.

Where data is stored

Account data in the European Union. Traffic in the region of the tunnel.

Account data
Account, billing and configuration data is stored in the European Union, backups included.
Tunnel traffic
Each tunnel runs in one region: EU, US or Asia Pacific. Its traffic passes through that region only.
Data protection
Localport applies the GDPR and the UK GDPR. A data processing addendum is available on request.

Report a vulnerability.

Write to security@localport.io. Misuse of a tunnel can be reported on the abuse page.