Security & Responsible AI

Trust must be designed into the workflow.

This page describes our current principles and product direction. It does not claim certifications or controls that have not been independently verified.

01

Workspace isolation

Product data and permissions are scoped to authenticated organizations and workspace membership.

02

Role-based control

Owners and administrators manage workspace roles, project creation permissions, and access boundaries.

03

AI activity records

Agent runs, prompts, outcomes, token use, and workflow events are designed for administrative visibility.

04

Secret handling

Production keys and database credentials belong in encrypted deployment configuration, never source control.

05

Bounded repair

Healing should preserve the intended test contract and stop when evidence indicates a product or environment issue.

06

Honest assurance

Security certifications will be listed only after formal completion and verification.

Report responsibly

Found a potential security issue?

Send a clear description and reproduction details privately. Please do not expose customer data or perform destructive testing.

Contact security