Credential handling
Cloud credentials are encrypted before storage and decrypted only server-side when Harbour needs to probe, refresh inventory, or fetch costs. Credentials are never returned to the browser after save.
- Use dedicated read-only provider credentials where possible.
- Rotate credentials from the provider console at any time.
- Audit events record environment creation and other mutating actions.