Destination security and limits

How Dcision protects outgoing requests — https only, SSRF guard, no redirects, secrets — what each destination type sends and stores, who can configure what, and every destination limit.

Outgoing requests

Webhooks, API requests, workflows and agents call URLs you configure, so Dcision guards every connection:

  • https only. A URL starts with https://, or with a secret that holds the whole URL. http:// URLs are refused when you save.
  • Public addresses only. The host name is resolved when Dcision connects, and every address is checked at that moment, inside the connection itself — a name can't resolve to a public address for the check and a private one for the request. Literal IP addresses are checked too.
  • No credentials in URLs. https://user:password@… is refused: put credentials in a header, with a secret.
  • No redirects. A 3xx answer is a failed delivery; Dcision never follows it.
  • Short and bounded. 10 seconds per delivery attempt (up to 25 seconds for LLM and sync agent calls), answers read up to 64 KB.

Blocked addresses:

RangeWhat it is
0.0.0.0/8"This" network
10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16Private networks
100.64.0.0/10Carrier-grade NAT
127.0.0.0/8Loopback
169.254.0.0/16Link-local, including cloud metadata services
192.0.0.0/24, 192.0.2.0/24, 192.88.99.0/24, 198.18.0.0/15, 198.51.100.0/24, 203.0.113.0/24Reserved, test and benchmarking ranges
224.0.0.0/4, 240.0.0.0/4Multicast, reserved and broadcast
::, ::1, fc00::/7, fe80::/10, fec0::/10, ff00::/8, 2001:db8::/32, 100::/64IPv6 unspecified, loopback, unique local, link-local, site-local, multicast, documentation and discard
IPv4-mapped, IPv4-compatible, NAT64 (64:ff9b::/96) and 6to4 (2002::/16) addressesBlocked when the IPv4 address inside is

Host names that end in .local, .internal or .localdomain — and names that resolve to any blocked address, such as internal service names — are refused too.

Secrets

  • Workspace secrets are encrypted with AES-256-GCM and never appear in the decision schema, responses, execution logs or the Playground — previews mask them as ••••.
  • The values of your headers are never written to Dcision's logs; keep tokens in secrets anyway, because the app shows a masked preview of every delivery's request, headers included.
  • The signing secret is encrypted too, and only Admins and the Owner can reveal or rotate it.

What leaves Dcision

TypeWhat the receiver gets
replyNothing leaves: the text is returned to the caller.
functionNothing leaves: the function name and params are returned to the caller.
llmThe model provider — under your key and account — gets the route's prompt and the input: the whole state unless you set input.
agentYour agent gets the whole state as input, the instructions, tools, params and the decision's answers.
webhookThe answers, confidence, weighted levels, composites, action, reason and params — never the state.
workflowThe params and the decision's answers — never the state.
httpExactly what your URL, headers and body template contain.

Map only what a receiver needs: params are the data-minimization tool of destinations.

What Dcision stores

  • The execution keeps the run's destinations entries — including function params, fixed replies, LLM texts and agent answers — whatever the decision's storeInput and storeOutput settings. They follow the execution's log retention and appear in GET /v1/executions. If params carry personal data, the entries do too.
  • Deliveries keep their status, attempts, the answer's status code, latency and first 1,024 characters, a masked preview of the request — method, URL, headers and the body's size, never the body — and, encrypted, the full request while it may be resent. They are deleted 30 days after they were created.

See Security and data for the rest of what Dcision stores.

Who can configure what

ActionViewerMemberAdminOwner
See destinations, deliveries and their status✓✓✓✓
Add, edit and deploy destinations—✓✓✓
Run destinations for real in the Playground—✓✓✓
Resend a failed delivery—✓✓✓
See secret names—✓✓✓
Manage secrets and the signing secret——✓✓
Save LLM provider keys (Settings → Engine)——✓✓

Limits

LimitValue
Destinations per decision20
Destinations that fire per execution10
LLM answers and sync agents per execution3
Conditions per destination5
Params per destination30
Fixed param valueup to 500 characters
Headers per destination20
Header valueup to 2,048 characters
URLup to 2,048 characters
http body templateup to 10,000 characters
Destination descriptionup to 2,000 characters
Reply textup to 4,000 characters
Reply buttonsup to 10, up to 80 characters each
LLM prompt, LLM input, agent instructionsup to 8,000 characters each
Agent toolsup to 50
LLM and sync agent timeout1,000 to 25,000 ms, default 20,000
LLM maxTokens16 to 2,048, default 512
LLM temperature0 to 2, default 0.3
Agent answer returned in responseup to 16,000 characters
Delivery attempts6, over about 7 hours
Delivery attempt timeout10 seconds
Deliveries per workspace600 per minute
Delivery retention30 days
Workspace secrets50, values up to 4,096 characters

On this page