olladns runs the same playbook we used as customers — encrypted-by-default DNS, scoped agent tokens, actor-attributed audit, and an honest answer to every CISO question. Here is the unvarnished posture, current today.
No marketing-speak. If a control is amber it means we're working on it and have a target month.
Per-tenant DoH paths route queries to per-tenant AdGuard Home client configs. Tenants never see each other's queries. Tenant identity is the DoH path component; DoT and DoQ carry no path and are refused. Plain Do53 is intentionally not exposed on the public LXC.
Axum + sqlx. Every write endpoint requires a scoped capability — humans get role-based access via JWT, agents get explicit resource:action scopes via X-API-Key. Cross-tenant writes are structurally impossible.
Query logs partition by tenant_id + day. 30-day default TTL, configurable per tenant. Anonymization toggle blanks client IPs at ingest. Bulk export ships CSV and NDJSON.
Every config change writes one row with actor_type (user / api_key / system), actor id, tenant id, action, and JSON metadata. Filterable by API-key id so you can audit a single agent's actions. Tamper-evident hash chain is on the roadmap.
TLS terminator + reverse proxy with per-key, per-IP rate limits. fail2ban watches Caddy 4xx storms and bans abusive IPs at the kernel firewall. Wildcard cert via Let's Encrypt with Cloudflare DNS-01 challenge.
FastMCP sidecar at mcp.olladns.com auto-generates tools from the OpenAPI spec and forwards the caller's X-API-Key on every upstream call. Sensitive ops (login, password change, key mint/rotate/delete) are excluded — humans only.
Each DNS query stores timestamp, client IP, query name, query type, response code, latency, and the blocklist that caught it (if any). Per-tenant retention defaults to 30 days; configurable up to 1 year on paid plans. Tenants who enable anonymization replace client_ip with an empty string at ingest — no separate reversible hash, just gone.
Email, bcrypt'd password hash, tenant id, role. Contact email is optional and used only for billing + incident notifications. We do not have or want your phone number.
Sha-256 hash of the key value only — we cannot recover a lost key. Label, scopes, optional expires_at, last_used_at. Deletion is permanent and instant.
Same retention as query logs (per-tenant configurable). Survives user deletion via ON DELETE SET NULL — the row remains, the foreign key goes to NULL, so the historical record of "key #9 modified policy X on date Y" is preserved even after that key is revoked.
olladns runs on a hardened Linux container (LXC) provisioned at a tier-3 datacenter, with full-disk encryption and isolated network namespaces. Cloudflare fronts the marketing site and provides DNS for the olladns.com zone (Cloudflare DNS only — the resolver itself is ours). Let's Encrypt issues TLS certificates via DNS-01 challenge.
India region (Mumbai) for data-residency-sensitive customers is on the roadmap. Until it ships, we cannot guarantee in-country storage — be explicit about that in your DPA negotiations.
Write to [email protected]. We respond within one business day with the SIG Lite + the current SOC 2 readiness status.
Reporting a vulnerability? See /security-policy for our disclosure process and bounty stance.