Security & Trust

Built for the people who get paged when something breaks.

olladns runs the same playbook we used as customers — encrypted-by-default DNS, scoped agent tokens, actor-attributed audit, and an honest answer to every CISO question. Here is the unvarnished posture, current today.

Posture, current today

What's done. What's in flight.

No marketing-speak. If a control is amber it means we're working on it and have a target month.

DNS encryption: DoHlive
DNSSEC validation enabled on every resolverlive
TLS 1.3 only, modern ciphers, HSTS preloadedlive
Scoped API keys with 12 resource:action scopes, optional expiry, instant rotation/revocationlive
Tamper-attributed audit log — every config change tags actor (human or agent token)live
Tenant isolation — server-stamped tenant_id on every write, never user-suppliedlive
Per-tenant + per-IP rate limiting at the edge (Caddy + fail2ban)live
Bcrypt password hashing, JWT sessions, no plaintext anywherelive
Public responsible-disclosure policy (see /security-policy)live
SOC 2 Type II auditobservation in progress
SAML / OIDC SSOroadmap
India region (Mumbai) for DPDP data-residencyroadmap
Penetration test (annual, third-party)scheduled
Architecture

How a DNS query flows through olladns.

DATA PLANE

Resolver isolation

Per-tenant DoH paths route queries to per-tenant AdGuard Home client configs. Tenants never see each other's queries. Tenant identity is the DoH path component; DoT and DoQ carry no path and are refused. Plain Do53 is intentionally not exposed on the public LXC.

CONTROL PLANE

Rust API, scope-aware

Axum + sqlx. Every write endpoint requires a scoped capability — humans get role-based access via JWT, agents get explicit resource:action scopes via X-API-Key. Cross-tenant writes are structurally impossible.

ANALYTICS

ClickHouse, tenant-partitioned

Query logs partition by tenant_id + day. 30-day default TTL, configurable per tenant. Anonymization toggle blanks client IPs at ingest. Bulk export ships CSV and NDJSON.

AUDIT

Actor-attributed, immutable

Every config change writes one row with actor_type (user / api_key / system), actor id, tenant id, action, and JSON metadata. Filterable by API-key id so you can audit a single agent's actions. Tamper-evident hash chain is on the roadmap.

EDGE

Caddy TLS, fail2ban, DDoS-hardened

TLS terminator + reverse proxy with per-key, per-IP rate limits. fail2ban watches Caddy 4xx storms and bans abusive IPs at the kernel firewall. Wildcard cert via Let's Encrypt with Cloudflare DNS-01 challenge.

AGENT

MCP server, scope-passthrough

FastMCP sidecar at mcp.olladns.com auto-generates tools from the OpenAPI spec and forwards the caller's X-API-Key on every upstream call. Sensitive ops (login, password change, key mint/rotate/delete) are excluded — humans only.

Your data

What we collect, where it lives, when it goes away.

Query logs

Each DNS query stores timestamp, client IP, query name, query type, response code, latency, and the blocklist that caught it (if any). Per-tenant retention defaults to 30 days; configurable up to 1 year on paid plans. Tenants who enable anonymization replace client_ip with an empty string at ingest — no separate reversible hash, just gone.

Account data

Email, bcrypt'd password hash, tenant id, role. Contact email is optional and used only for billing + incident notifications. We do not have or want your phone number.

API keys

Sha-256 hash of the key value only — we cannot recover a lost key. Label, scopes, optional expires_at, last_used_at. Deletion is permanent and instant.

Audit log

Same retention as query logs (per-tenant configurable). Survives user deletion via ON DELETE SET NULL — the row remains, the foreign key goes to NULL, so the historical record of "key #9 modified policy X on date Y" is preserved even after that key is revoked.

Hosting & subprocessors

Where olladns runs.

olladns runs on a hardened Linux container (LXC) provisioned at a tier-3 datacenter, with full-disk encryption and isolated network namespaces. Cloudflare fronts the marketing site and provides DNS for the olladns.com zone (Cloudflare DNS only — the resolver itself is ours). Let's Encrypt issues TLS certificates via DNS-01 challenge.

India region (Mumbai) for data-residency-sensitive customers is on the roadmap. Until it ships, we cannot guarantee in-country storage — be explicit about that in your DPA negotiations.

Full subprocessor list (coming with the legal page)

Questions

Security inquiry, vendor risk questionnaire, or DPA?

Write to [email protected]. We respond within one business day with the SIG Lite + the current SOC 2 readiness status.

Reporting a vulnerability? See /security-policy for our disclosure process and bounty stance.