Skip to main content

Security

Layered controls for tenant-isolated, versioned work.

Access

Default-deny authorization combines organization membership, explicit project access, capabilities, assignment, record state, and row-level security. MFA is required for organization owners and administrators and can be required more broadly by policy.

Data handling

Private Storage, authenticated downloads, fail-closed malware scanning, append-only histories, soft deletion, recovery, legal holds, and auditable support access reduce common SaaS risks.

Scope of statements

These are product design statements, not a certification, warranty, SLA, penetration-test result, or claim of regulatory compliance. A final externally approved security statement is required before commercial launch.