WND customer portal: security summary
For security reviewers. The portal is where your IT team downloads WND Terminal and manages who at your company can. WND Terminal itself doesn't depend on it: installed copies keep working whatever happens to the portal.
Who can get in
- Invitation only: your company's portal admins (or WND) invite people, in two roles, Admin and Downloader. The one exception is a switch your admins control: with your company login connected, they can let in anyone your login lets through, as a Downloader.
- Sign-in is by a one-time code sent to the work email, or your own company login (SAML: Okta, Microsoft Entra ID and others). There are no portal passwords.
- Your admins can require your company login for your verified email domains (proven by a DNS record), so removing someone from your directory stops them signing in again. A company login can only sign in addresses at its own verified domains.
- Sessions last 12 hours. Removing a person in the portal, or the end of your contract, signs them out at once.
- Each sign-in has to finish in the browser that started it, and the person must come back as the same sign-in identity.
- Sign-in attempts are rate-limited per address and per network; the address gets an email if its sign-in is paused.
- WND staff use a separate console with a second factor (an authenticator app). Staff can't sign in as your people, and anything staff change on your account, invitations included, shows in your activity.
The installers
- Built by our build pipeline and stored in private storage that only the pipeline can write to; each release is stored once and never overwritten.
- Every file has a published SHA-256 checksum on the downloads page.
- The portal only publishes a release to the stable channel when our build pipeline has marked it code-signed (Windows) and notarized by Apple (Mac). Preview builds are labeled as previews.
- Each download link works for 10 minutes and only for the person who clicked it, so links can't be passed around.
What we store, and where
| Your company | Name, email domains, seats, contract dates, single sign-on settings. |
|---|---|
| Your people | Name, work email, role, last sign-in. No passwords, no payment details. |
| Activity | Sign-ins and refused sign-ins, invitations, role and single sign-on changes, contract changes and downloads: who, what, when, and from which IP address. Kept for 2 years, then deleted. |
| Where | The portal, its database and the installer storage run on Cloudflare in the United States. Sign-in is handled by Kinde (United States) and emails are sent by Resend (United States). |
Your portal admins can see your company's activity and export it as CSV at any time.
In the browser
- HTTPS only, with strict security headers (a content security policy, no framing).
- No third-party scripts, analytics or trackers on portal pages.
Questions
For our security pack or to report a security issue, contact us.