SECURITY
Security is enforced through identity, tenant boundaries, entitlements, and governed actions.
This page describes the current Public Beta security posture. It is a technical overview, not a certification or contractual security schedule.
ACCESS CONTROL
Authenticated and organization-scoped.
- Supabase Authentication protects customer access.
- Organization membership is validated before protected workspace access.
- Owner-only management paths enforce role-aware checks.
- Password recovery uses single-use authentication links and PKCE session exchange.
DATA ACCESS
Tenant-aware database enforcement.
- Row Level Security policies scope supported data access to the active organization.
- Commercial catalog writes are restricted and governed mutations are server-controlled.
- Pending commercial entitlements cannot use activated product capabilities.
- The public Demo uses synthetic fixtures and does not expose production tenant data.
AI GOVERNANCE
AI authority is bounded by product controls.
- Agent roles include authority and risk boundaries.
- External actions remain locked by default in the Public Beta.
- Approval-requiring work is designed to stop at a human decision boundary.
- Traceability links intent, evidence, meetings, decisions, approvals, and actions.
CURRENT LIMITS
Public Beta is not a security certification.
- No SOC 2 or ISO 27001 certification is currently claimed.
- Enterprise use should undergo customer-specific security and data review.
- Do not treat the public Demo as a place for confidential or production information.
- Security controls and documentation may be strengthened during the Beta.
SECURITY REPORTING
Found a security issue?
Do not include passwords, access tokens, private keys, or unrelated customer data in an initial report. Provide the affected URL, reproduction steps, expected behavior, and observed behavior.