SECURITY

Security by product design

The platform is being designed around least privilege, tenant isolation, explicit consent, auditable actions, and honest integration states.

STATUS

Architecture commitment
01

Access boundaries

Sensitive actions are designed for server-side authorization, fresh role checks, short-lived scoped links, and object-level permission checks.

02

Data and integrations

Private files remain private by default; external events require signature and replay checks; secrets stay server-side; logs exclude private message and file bodies by default.

03

AI and realtime

Retrieved content is treated as untrusted evidence, tools are allowlisted, AI identity is disclosed, and recording remains off until explicit consent policy is active.

QUESTIONS

Need a direct answer before final policy publication?

Use the contact route and state which policy or data practice you need clarified.

Security | Tarkora Labs