SECURITY

Security is enforced through identity, tenant boundaries, entitlements, and governed actions.

This page describes the current Public Beta security posture. It is a technical overview, not a certification or contractual security schedule. Reviewed 1 September 2026.

ACCESS CONTROL

Authenticated and organization-scoped.

  • Supabase Authentication protects customer access.
  • Organization membership is validated before protected workspace access.
  • Owner-only management paths enforce role-aware checks.
  • Password recovery uses single-use authentication links and PKCE session exchange.

DATA ACCESS

Tenant-aware database enforcement.

  • Row Level Security policies scope supported data access to the active organization.
  • Commercial catalog writes are restricted and governed mutations are server-controlled.
  • Pending commercial entitlements cannot use activated product capabilities.
  • The public Demo uses synthetic fixtures and does not expose production tenant data.

EXECUTION SECURITY

Tool use is separated from model output.

  • Supported actions pass through a centralized Integration and Execution Gateway.
  • Capability, scope, Agent permission, user permission, entitlement, environment, risk and approval are evaluated separately.
  • Execution requests use tenant-scoped records and idempotency controls where the operation supports them.
  • High-impact actions require an exact, bounded human approval rather than a reusable blanket approval.

CONTROL OWNERSHIP

Current controls are operated by the RYTHM Public Beta provider.

  • RYTHM operates application authorization, gateway policy, tenant-aware data controls and the documented incident channel.
  • Infrastructure subprocessors operate their respective hosting, database, AI or communication services as disclosed in the Subprocessor Register.
  • Customers remain responsible for authorized users, submitted data, connected accounts, local legal requirements and their own deployment decisions.
  • Enterprise customers should request a control and data-flow review before sensitive deployment.

SECURITY QUESTIONS

Material Public Beta answers

Is RYTHM SOC 2 or ISO 27001 certified?

No. RYTHM does not currently claim SOC 2, ISO 27001, or another third-party security certification.

Where is tenant isolation enforced?

Tenant boundaries use authenticated organization context, application checks, Supabase Row Level Security, and organization-scoped execution and operating records.

Can an Agent access every connected tool?

No. A connection does not grant universal access. Provider scope, organization grant, Agent capability, user permission, risk, approval and rollout state are checked separately.

How should a vulnerability be reported?

Send the affected URL, reproduction steps, expected behavior and observed behavior to security@rythm-os.com. Do not include secrets or unrelated customer data in the initial report.

AI GOVERNANCE

AI authority is bounded by product controls.

  • Agent roles include authority and risk boundaries.
  • External actions remain locked by default in the Public Beta.
  • Approval-requiring work is designed to stop at a human decision boundary.
  • Traceability links intent, evidence, meetings, decisions, approvals, and actions.

CURRENT LIMITS

Public Beta is not a security certification.

  • No SOC 2 or ISO 27001 certification is currently claimed.
  • Enterprise use should undergo customer-specific security and data review.
  • Do not treat the public Demo as a place for confidential or production information.
  • Security controls and documentation may be strengthened during the Beta.

SECURITY REPORTING

Found a security issue?

Do not include passwords, access tokens, private keys, or unrelated customer data in an initial report. Provide the affected URL, reproduction steps, expected behavior, and observed behavior.

Report responsibly

Email Security

security@rythm-os.com