Skip to content

Security Practices

The practices below are what we operate today.

Each customer’s data is scoped to that customer at the data-access layer, not just hidden in the interface. A request from one customer’s account cannot read another customer’s records.

  • Every API request requires a bearer token.
  • Accounts carry roles (admin, reviewer, read-only) that limit what each user can do.
  • Administrative surfaces are restricted to admin roles.
  • Transport encryption everywhere: HTTPS for the web surfaces and TLS for data connections.
  • Per-endpoint rate limiting with backoff signaling to absorb abusive traffic.
  • An audit trail records sensitive actions.
  • Application errors and exceptions are monitored with alerting.
  • The platform’s health endpoints report degraded state rather than failing silently.

If you believe you have found a security issue, see Vulnerability disclosure.