Security

DeviceLink is designed with security at every layer. Here is how we protect your data.

Data in Transit

All communication between your device, the DeviceLink bridge, and MCP clients is encrypted using TLS. The specific TLS version depends on infrastructure configuration and is kept current with industry standards.

Data at Rest

The DeviceLink agent stores device credentials locally using AES-256-GCM encryption with keys derived from your machine identity via PBKDF2. No plaintext credentials are written to disk.

File contents are never stored on DeviceLink servers. They are streamed in real-time between your device and the requesting client.

To be precise about what this is not: DeviceLink is not end-to-end encrypted. Our bridge terminates the TLS connection in order to route a request, so file contents pass through our servers in memory. They are never written to disk, cached, or logged.

Authentication

  • OAuth 2.0 with PKCE (S256) for user authentication via Google, GitHub, or Microsoft
  • Optional email and password sign-in, stored as a scrypt hash with a per-account salt, never as plaintext
  • ES256 (ECDSA P-256) JWT tokens for API and MCP access
  • Ed25519 proof-of-possession signatures for device identity verification
  • Device authorization requires explicit user consent through a browser-based verification flow
  • Short-lived access tokens with automatic refresh

Local-First Architecture

DeviceLink operates on a local-first principle. Your files remain on your device. Access is granted only to directories you explicitly share, and only while the agent is running. You can disconnect at any time.

  • Path traversal protection prevents access outside shared directories
  • Symlink and junction escape detection prevents boundary bypasses
  • Configurable ignore rules filter sensitive files

Audit Logging

Security-relevant actions - sign-ins, device approvals, access changes, tool calls - are recorded in an audit log that organization administrators can review. Entries record the acting account, the IP address and browser the request came from, and the result. See the privacy policy for what is kept and for how long.

Report a Vulnerability

If you discover a security vulnerability, please report it responsibly via our support page. We take all reports seriously and will respond promptly.

Last updated: September 2026