Security Practices
The practices below are what we operate today.
Data isolation
Section titled “Data isolation”Each customer’s data is scoped to that customer at the data-access layer, not just hidden in the interface. A request from one customer’s account cannot read another customer’s records.
Access control
Section titled “Access control”- Every API request requires a bearer token.
- Accounts carry roles (admin, reviewer, read-only) that limit what each user can do.
- Administrative surfaces are restricted to admin roles.
Network and application protections
Section titled “Network and application protections”- Transport encryption everywhere: HTTPS for the web surfaces and TLS for data connections.
- Per-endpoint rate limiting with backoff signaling to absorb abusive traffic.
- An audit trail records sensitive actions.
Monitoring
Section titled “Monitoring”- Application errors and exceptions are monitored with alerting.
- The platform’s health endpoints report degraded state rather than failing silently.
What to report
Section titled “What to report”If you believe you have found a security issue, see Vulnerability disclosure.
More detail
Section titled “More detail”- Access control: authentication, roles, and rate limiting.
- Data isolation: how tenant data stays separated.
- Infrastructure: hosting and delivery.
- Backups & recovery: backup scheduling and restore.