← All posts
Engineering

How we keep X sessions alive securely

Persistent logins without keeping passwords: envelope encryption, isolation and health checks.

Never store passwords

The first rule of session management: do not store credentials. Run Pilots never sees your password — login happens in a hosted live browser that you watch, and we capture the resulting session state only.

Envelope encryption

Each browser profile is encrypted with its own AES-256-GCM data key. Those keys are wrapped by a master key that lives only in the deployment environment. A stolen database dump yields ciphertext and nothing usable.

Keeping sessions healthy

Sessions degrade quietly. A keepalive job visits each connected account on a schedule, verifies it is still signed in, and raises a re-login notification the moment it is not. Reconnecting takes one click and thirty seconds.

Ready when you are

Try what you just read

Connect an account and run your first scheduled flight tonight.

7-day refund · Cancel anytime · No API keys · Encrypted by default