Security
Here you'll find articles about CircleCI's security features to keep your pipelines safe, including OIDC, rotating secrets, and information on our SOC 2 and FedRAMP compliance.
28 articles
- How CircleCI protects against brute-force and credential stuffing attacksOverview of the authentication protections CircleCI has in place against brute-force and credential stuffing, and what users can do to further protect their accounts.
- CircleCI MCP Server: Security Model and Safe DeploymentExplains that the CircleCI MCP server is designed for local use only, the risks of exposing it to untrusted networks, and how to deploy it safely.
- What logs can CircleCI provide for audit and forensic analysis?This article explains which logs CircleCI Cloud makes available for audit and forensic analysis, how organization admins can request them, and what is included in the self-serve audit log export.
- Rotating the GitHub webhook secret for CircleCI GitHub OAuth project triggers
- Account Flagged for Acceptable Use Policy Violation
- Why I can't request audit logs?
- Cannot Build: All Triggers Stuck on "Not Run" Status
- Restricting access to contexts
- Accessing Security Documentation on the Performance Plan
- What to do if you suspect you have a secret leaked from CircleCI
- How to review all config policy warnings?
- My Current CircleCI Session Gets Logged Out When I Open Another One
- Who Canceled my Approval Job?
- How do I report a security vulnerability?
- How to request a security questionnaire
- Best Practices for Rotating User SSH keys and Additional SSH keys
- Best Practices of API Token Rotation
- Rotating Secrets for January 4th Incident
- Where to Find GDPR and DPA Information
- How to View SOC2 and FedRAMP Information
- SOC 2 and FedRAMP Reports
- IP Address Ranges for Safelisting/Do You Have Static IP Addresses Available?
- Pipeline Values You Can Use in Context Expression RestrictionsContext expression restriction examples are illustrations, not a whitelist. You can restrict a context by branch, repository name, owner, SSH, and other pipeline values, and you can combine them.
- Using GitHub IP allow lists with CircleCI OAuth and the GitHub AppConfiguration of GitHub IP allow lists with CircleCI
