Security
Layered controls for tenant-isolated, versioned work.
Access
Default-deny authorization combines organization membership, explicit project access, capabilities, assignment, record state, and row-level security. MFA is required for organization owners and administrators and can be required more broadly by policy.
Data handling
Private Storage, authenticated downloads, fail-closed malware scanning, append-only histories, soft deletion, recovery, legal holds, and auditable support access reduce common SaaS risks.
Scope of statements
These are product design statements, not a certification, warranty, SLA, penetration-test result, or claim of regulatory compliance. A final externally approved security statement is required before commercial launch.