Security
Here you'll find articles about CircleCI's security features to keep your pipelines safe, including OIDC, rotating secrets, and information on our SOC 2 and FedRAMP compliance.
25 articles
- How CircleCI protects against brute-force and credential stuffing attacksOverview of the authentication protections CircleCI has in place against brute-force and credential stuffing, and what users can do to further protect their accounts.
- CircleCI MCP Server: Security Model and Safe DeploymentExplains that the CircleCI MCP server is designed for local use only, the risks of exposing it to untrusted networks, and how to deploy it safely.
- Rotating the GitHub webhook secret for CircleCI GitHub OAuth project triggers
- Account Flagged for Acceptable Use Policy Violation
- Why I can't request audit logs?
- Cannot Build: All Triggers Stuck on "Not Run" Status
- Restricting access to contexts
- Accessing Security Documentation on the Performance Plan
- What to do if you suspect you have a secret leaked from CircleCI
- How to review all config policy warnings?
- My Current CircleCI Session Gets Logged Out When I Open Another One
- Who Canceled my Approval Job?
- How do I report a security vulnerability?
- How to request a security questionnaire
- Best Practices for Rotating User SSH keys and Additional SSH keys
- Best Practices of API Token Rotation
- Rotating Secrets for January 4th Incident
- Where to Find GDPR and DPA Information
- How to View SOC2 and FedRAMP Information
- SOC 2 and FedRAMP Reports
- IP Address Ranges for Safelisting/Do You Have Static IP Addresses Available?