Skip to main content
This section covers how Infisical works underneath: the components it is built from, the security properties it guarantees, and how permissions are evaluated.

Architecture and security

The parts Infisical is built from, how Infisical Cloud is deployed, and the encryption and isolation model.

Permissions

How the permission system evaluates access, and the full list of what each action grants.

Service tokens

How a service token is structured, and how to scope, store, and rotate one safely.
You don’t need to read this section to use Infisical. It is worth reading if you operate an instance, or if you are answering security questions about how Infisical handles your data.