Security
Security is a design property, not a feature. Isolation, least privilege, and auditability are enforced by the platform — and verified by automated checks.
Company isolation
Each company operates in an isolated environment with separate data, credentials, and audit trail. Verified by automated isolation checks — 12/12 passing.
Least-privilege credentials
Every integration uses scoped credentials with the minimum permissions needed. Cloudflare access, for example, is limited to DNS and object storage — no broad keys.
Append-only audit
AI executions, approvals, and timeline events are append-only. The audit trail is visible in the Control Centre and cannot be silently rewritten.
Secrets never in the frontend
No API keys, tokens, or credentials in browser code. Secrets live in environment variables or the encrypted secrets store, mounted read-only.
Secret scanning
Every release is scanned for leaked secrets (gitleaks). Latest scan: 0 leaks found across the repository.
Governed access
Operator authentication is required for control-plane actions. The authorization source is verified server-side — never trusted from the client.
Security posture
| Control | Status | Detail |
|---|---|---|
| Secret scanning | VERIFIED | gitleaks: 0 leaks (6.69 MB scanned) |
| Company isolation | VERIFIED | 12/12 automated checks passing |
| Operator auth | VERIFIED | Session-based, server-verified |
| Outbound governance | VERIFIED | PILOT mode, human approval required |
| Dependency audit | PARTIALLY VERIFIED | npm audit run per release |
Questions about security?
Book a discovery call to review the security model in detail.
Book a Discovery