For the complete documentation index, see llms.txt. This page is also available as Markdown.

Security overview

Apply least privilege and explicit ownership across the Unitlab operating model.

Unitlab security is a set of connected identity, access, credential, data-handling, and operational controls. The organization remains responsible for configuring those controls according to its data classification and regulatory obligations.

Use this area when: you are onboarding a workspace, connecting cloud storage, issuing API keys, handling sensitive data, or reviewing production access.

How this area fits into production

Personal Account security page with password and two-factor authentication controls

Personal Settings › Account security is the human sign-in control surface. It shows password management, 2FA status, the Enable 2FA action, and the account danger zone; role-based authorization is configured separately at workspace and project scope.

What this area controls

Unitlab supports email/password sign-up and sign-in, Google authentication, email verification, invitation-token access, password reset, and TOTP two-factor authentication.

Two-factor authentication includes QR/secret setup, verification, ten single-use backup codes shown once, login challenge, disable, and backup-code regeneration. When 2FA is enabled, password change, password-reset completion, account deletion, and workspace destruction require an appropriate second factor.

If a user refreshes during the temporary 2FA login challenge, the challenge is cleared and the user returns to login rather than leaving reusable sensitive state in the browser.

Start with the right page

Decision
Production guidance

Protect sign-in

Change compromised passwords and enable TOTP two-factor authentication in Personal Settings › Account security.

Control access

Use workspace roles, permission groups, project assignment, and workflow eligibility.

Protect automation

Create, store, rotate, disable, and delete API keys from Workspace Settings › API keys.

Connect source systems

Add cloud storage with a dedicated least-privilege identity and exact prefix.

Handle sensitive data

Apply organization policy to screenshots, exports, logs, source paths, and releases.

Remove access

Use the offboarding runbook and verify denial after ownership transfer.

Operating boundary

  • Do not place secrets, signed URLs, regulated content, or private source paths in public docs or tickets.

  • A personal user credential is not a service identity strategy.

  • Access reviews must include in-flight tasks, integrations, model endpoints, keys, and release destinations.

A production-ready handoff

Every privileged identity and connection has an owner, minimum scope, approved secret location, rotation and revocation path, review date, and tested failure behavior.


Explore related Unitlab capabilities: AI training-data annotation