Security
What Hela does so integrations do not open the door.
Secrets
- Connection credentials (keys, tokens, certificates) are encrypted AES-256-GCM before being written, with a versioned
INTEGRATIONS_KEY: a key rotation requires no manual re-encryption, the old one stays readable during the switch. - They are never returned by the API nor shown on screen; a set field reads Set.
- API keys are stored only as their SHA-256 digest; webhook secrets, encrypted like credentials.
- Connection logs are scrubbed: a recognisable token (
Bearer …,sk_live_…,whsec_…,hela_live_…, a long opaque string) appearing in a partner's answer is replaced with•••before being written.
API keys
- Scopes: an explicit subset of permissions; permissions touching the account's people and money are forbidden to keys.
- Test mode: read-only, by construction.
- Rate limit per key, and
429beyond. - Immediate revocation.
- Every key request is logged in the company's audit with the key's prefix (
request_events).
Outgoing webhooks
- HTTPS required; private, local and link-local addresses refused at creation and on every delivery (DNS resolution checked: a name pointing to
10.0.0.1is refused); redirects not followed; 15-second timeout. - Timestamped HMAC-SHA256 signature on every delivery; five-minute validity window.
- No body beyond what the event carries: never a secret, never another customer's data.
Incoming webhooks
- One address per connection, not guessable (
/integrations/inbound/<provider>/<connection id>). - The partner's signature is verified when it provides one (Stripe, Mollie, Wave, Flutterwave, Yousign, DocuSign, M-Pesa, MTN…); otherwise the event is read back from the partner before being believed. A notification matching nothing is logged and ignored.
- The raw body is kept for verification, never interpreted first.
OAuth
- Authorization code flow with PKCE and a signed, single-use state bound to the company and the user who clicked; ten minutes' validity.
- Minimal scopes:
drive.file(one folder),Files.ReadWrite.AppFolder, and never full access to a Drive or a mailbox. - Refresh tokens are encrypted like the rest; reconnection is requested when the partner revokes them.
Company isolation
Every company has its database schema; connections, keys, webhooks and jobs carry the company id and are filtered by it in every query. One company's API key cannot name another company in a path: 404.
Fiscal regimes
- Certificates and private keys (VFD, EFRIS) are encrypted like other credentials; signatures are computed server-side and the key never leaves the database.
- The sealed journal makes any later change visible, which protects the company as much as the administration.
Reporting
A vulnerability is reported to security@hela.co. We acknowledge within 48 hours and publish a fix before publishing the detail.