SECURITY
Security by product design
The platform is being designed around least privilege, tenant isolation, explicit consent, auditable actions, and honest integration states.
STATUS
Architecture commitment01
Access boundaries
Sensitive actions are designed for server-side authorization, fresh role checks, short-lived scoped links, and object-level permission checks.
02
Data and integrations
Private files remain private by default; external events require signature and replay checks; secrets stay server-side; logs exclude private message and file bodies by default.
03
AI and realtime
Retrieved content is treated as untrusted evidence, tools are allowlisted, AI identity is disclosed, and recording remains off until explicit consent policy is active.
QUESTIONS
Need a direct answer before final policy publication?
Use the contact route and state which policy or data practice you need clarified.