Skip to content
WLOC Cloud

Security · Minimize · Isolate · Recover

Security is a boundary you can inspect.

See how WLOC Cloud limits browser access, isolates tenant-scoped operations, minimizes stored data, labels evidence honestly, and keeps recovery controls reachable.

Engineering controls and automated tests · Independent review pending · No certification badge implied

System trust boundary

Four layers, four separate responsibilities.

The browser does not connect directly to the data plane. Passing one security boundary never silently upgrades the evidence produced by the next layer.

  1. 01Browser intentDeclare the test
  2. 02Control planeAuthorize and scope
  3. 03Device coordinationSerialize one device
  4. 04Execution and confirmationApply, observe, confirm
  • Browser never connects directly to the Gateway
  • Profile XML and EAP passwords are not persisted by the control plane
  • Target synced is not labeled device online
  • Restore controls remain available in every account state

Data minimization

Store less. Separate what remains.

These are product and architecture contracts, not a claim of external certification. The public Privacy Policy is effective; the separate Cloud engineering legal documents remain formal-review drafts.

Control-plane data

Only what the product needs

Account email, workspace and device metadata, policy acceptance, entitlement references, bounded target coordinates, operation state, and redacted audit events.

Never persisted

Sensitive material is not retained

Profile bytes and the EAP password transit Worker memory into an explicit one-time, no-store download. They are not retained in control-plane databases, KV, Durable Objects, queues, analytics, structured application logs, or fixtures.

Logs and analytics

Allowlist first, redact again

WLOC structured application logs use field allowlists and redaction. Product analytics excludes email addresses, precise coordinates, tokens, device secrets, and Profile payloads.

The Profile is security-sensitive configuration.

It includes a CA root certificate, IKEv2 payload, and EAP credentials. WLOC does not call it a signed Profile until CMS verification is proven, and it does not call device-specific credentials hardware-bound. Review the install and removal guide before continuing.

Access control

Authorization is enforced server-side.

UI state is never treated as an access-control decision. Every protected operation must re-establish identity, scope, capability, and mutation safety at the API boundary.

Control 01

Tenant-scoped queries

Workspace and resource scope are checked together before an operation is loaded.

Control 02

Protected mutations

Mutation requests require an authenticated session, exact-origin controls, and CSRF protection.

Control 03

Privileged recovery

High-risk support actions require separate identity, recent authentication, a reason, user authorization, and audit.

Control 04

Separated marketing surface

The marketing Worker has no Cloud product-data binding; operational data stays in the Cloud control plane.

Evidence semantics

A successful call is not a universal result.

WLOC separates control-plane intent, Gateway readback, device evidence, and the tester's target-app confirmation. Labels state exactly which layer produced the evidence.

target_synced

Gateway target synced

Supports
The Gateway accepted and stored the requested test target for the scoped device operation.
Does not establish
It does not prove that the iPhone is online or that the target app adopted the result.
awaiting_confirmation

Awaiting confirmation

Supports
The control-plane operation has evidence, while the device or target-app result still needs a human check.
Does not establish
It is not automatically a failed test and must not be upgraded to a green success state.
restore_submitted

Restore submitted

Supports
The Restore request was accepted for processing.
Does not establish
It does not prove tunnel termination or that normal location is already visible on the device.
manual_confirmation

Device and app checked

Supports
The tester records what the authorized device and target app actually show after apply or restore.
Does not establish
One observed result does not establish compatibility for every app, device, network, or iOS version.

Recovery contract

Recovery controls do not depend on a paid state.

Restore, Revoke, Emergency Stop, Export, and Delete Account remain reachable under unpaid, refunded, frozen, restricted, and pending-deletion states. New Apply or Provision may be unavailable; only a server-enforced gate is treated as access control. Restore remains reachable.

Report a security concern without sending secrets.

Contact support@wloc.app with a reproducible description and redacted timestamps. Do not email Profile XML, EAP credentials, tokens, private keys, or raw traffic. No response-time SLA or external security certification is claimed here.

Review before you connect

Understand the boundary, then run a bounded test.

Start with the fixed Tokyo Tower diagnostic, inspect each evidence layer, and finish with a device-side Restore check.

Sign in to check eligibilityRead the Cloud model

Authorized devices only · No card required · Restore remains reachable