Security at Localport.
What Localport can see, what it records, who holds the keys and how access is removed.
Built on security and privacy.
The summary, then the detail a security review needs.
- Traffic content is never logged
- Only connection metadata is recorded.
- Keys stay on the device
- Private keys never leave the machine that holds them.
- Access ends immediately
- Removing access closes open connections.
- Open-source agent
- The code that runs on your machines is public.
What Localport can see
It depends on the kind of connection.
- TLS tunnels
- Traffic stays encrypted all the way to your service. Localport holds no key for it and cannot decrypt it.
- TCP tunnels
- Bytes are forwarded as they arrive and are not inspected. A protocol that encrypts itself, such as SSH, stays encrypted.
- HTTP and HTTPS tunnels
- Localport serves HTTPS with its own certificate. A request is decrypted in memory to apply the rules set on the tunnel, then forwarded to the agent over an encrypted connection. Nothing is written to disk.
- Remote Access
- The caller's certificate is verified, then traffic is forwarded to the device over an encrypted connection. Nothing is written to disk.
- Agent connection
- Every connection between the agent and Localport uses TLS 1.3.
What is recorded
Metadata about connections only.
- Connection metadata
- Connection counts, bytes transferred, request counts, session start and end times, region, agent version and disconnect reasons. Used for billing, operations and abuse handling.
- Access log
- For Remote Access: the identity that connected, the device and port, the source address, the time, the outcome, the duration and the traffic volume. Readable by the team's admins.
- Audit log
- Administrative changes in a team: who made the change, what changed, when and from which address. The address is removed from an entry after 90 days.
- Never recorded
- Request paths, headers, bodies and payloads.
Keys and credentials
Every credential is a certificate, and no private key is ever sent to Localport.
- Private keys
- A key is generated where it will be used, by the agent or in the browser. Only a signing request is sent. Localport has no way to receive a private key.
- People
- A member signs in with localport login and approves the request in the browser. The certificate lasts hours and is not renewed.
- Machines
- A machine redeems a single-use setup key, then renews its own certificate. No long-lived secret stays on the machine.
- CI pipelines
- A pipeline proves its identity with an OIDC token from its own platform. No secret is stored. The certificate lasts 15 minutes and is held in memory.
- Bring your own CA
- An existing certificate authority is registered for verification only, with its revocation list. Its private key is never uploaded.
- Tunnel tokens
- Stored as a SHA-256 hash, with an AES-256-GCM encrypted copy for display in the dashboard. Rotating a token stops the old one immediately.
How access is decided
Nothing is reachable until it is allowed.
- Private by default
- A fleet device accepts no connection without a certificate and a grant. A certificate with no grant reaches nothing.
- Explicit grants
- Access is granted to a member, a role or a machine, for one device, a group of devices or the whole fleet. Nothing is allowed implicitly.
- Tunnel protection
- IP allowlist, basic auth, header authentication and webhook signature verification. Each is checked on every request.
- Source restriction
- A tunnel can be limited to agents connecting from listed addresses, so a leaked token alone cannot bring it online.
- Dashboard sign-in
- The dashboard supports passkeys, and a team can require them for its members.
How access is removed
Each of these takes effect on connections that are already open.
- Revoke a certificate
- Connections using that certificate close.
- Remove or narrow a grant
- Connections the grant covered close.
- Remove a device
- The device is disconnected and its agent stops reconnecting. With auto-join off, it cannot join again.
- Remove a certificate authority
- Connections that relied on it close.
- Remove a team member
- Their access ends on every fleet and their connections close.
The agent
The one piece of Localport installed on your machines.
- Open source
- The agent is published on GitHub under the Apache 2.0 licence.
- Outbound only
- The agent connects out on port 443. No inbound port is opened on the machine or its network.
- TLS 1.3
- Required on every connection the agent makes. No setting lowers it.
- Signed releases
- Release checksums are signed, and the installer verifies them before it installs.
- Key files
- The agent refuses a private key file that other users on the machine can read.
- No personal data
- A stored credential holds a username, a team id and a team name.
Where data is stored
Account data in the European Union. Traffic in the region of the tunnel.
- Account data
- Account, billing and configuration data is stored in the European Union, backups included.
- Tunnel traffic
- Each tunnel runs in one region: EU, US or Asia Pacific. Its traffic passes through that region only.
- Data protection
- Localport applies the GDPR and the UK GDPR. A data processing addendum is available on request.
Report a vulnerability.
Write to security@localport.io. Misuse of a tunnel can be reported on the abuse page.