Security

What we do with your work, and who can reach it

Written to be checkable. Where something is not built yet, this page says so rather than leaving you to find out.

The client is never trusted

Every permission is decided on the server, from the same table, on every request. Hiding a button is a courtesy to the person using the app — it is never what stops an action. Posting directly to the API reaches exactly the same checks the interface does.

Roles are resolved against the workspace named in the URL rather than a “current workspace” held in your session, so two open tabs cannot be used to act on one workspace with permissions from another.

Accounts

  • An address must be confirmed before it gets a session. Signing up does not sign you in.
  • Passwords are salted and hashed. They are stored apart from your profile and are never written to logs.
  • Sign-up returns the same response whether or not an address already has an account, so the form cannot be used to find out who is a customer.
  • Sign-in and sign-up are rate limited.
  • An invitation link only works for the address it was sent to. Signing up as somebody else leaves the invitation unusable.

Files

  • Buckets are private. There is no public URL for anything you upload.
  • Downloads go through a short-lived link issued only after your membership and role have been checked for that specific file.
  • Uploads go straight from your browser to storage, so your media never passes through an application server.
  • Nothing is transcoded or re-encoded. What you download is byte-for-byte what was uploaded.

Workspaces are sealed from each other

Every query is scoped to a workspace, and a valid identifier from a workspace you do not belong to resolves to nothing. Asking for one returns “not found” rather than “forbidden” — a forbidden would confirm the thing exists.

There is a record

Submissions, approvals, rejections, reopenings and membership changes are written to an audit trail as they happen, in the same transaction as the change itself. An event cannot go missing because something failed halfway.

Not built yet

Listed because you should know before you decide, not after:

  • Two-factor authentication.
  • Single sign-on and SCIM provisioning.
  • Independent certification. We have not been audited against SOC 2, ISO 27001 or anything else, and this page is a description rather than an attestation.
  • Customer-managed encryption keys.

Telling us about a problem

If you find something, please report it before disclosing it publicly, and give us a reasonable window to fix it. We will not pursue anyone who reports a genuine issue in good faith.