1. Scope and status
This document is a draft for founder and legal review. It is not legal advice and does not create a commitment until approved and published.
This overview describes controls observed in the current repository. It is not a certification, audit report, uptime commitment, or guarantee of security for every deployment.
2. Tenant isolation
Tenant-aware services, authorization checks, and selected PostgreSQL RLS protections are used in platform paths. Customers must still configure Workspace users, provider access, Actions, Workflows, and webhook destinations carefully.
3. Secrets and credentials
Environment-based secrets, signed provider callbacks, signed outbound webhooks, and encrypted webhook-secret storage are present in supported paths. Do not expose service-role keys or provider secrets in client code.
4. Transport and endpoints
Supported HTTPS integrations and endpoint validation are used where implemented. Provider and network behavior can vary; this page does not claim a universal TLS version or end-to-end encryption for every data path.
5. Access and authentication
Authentication callbacks, session behavior, tenant checks, and route-level authorization are part of the observed application. Customers are responsible for user access, credential hygiene, and prompt reporting of unauthorized activity.
6. Execution evidence
Action and Workflow evidence records technical execution state. It does not prove a business outcome, caller intent, legal basis, or correctness of AI interpretation.
7. Infrastructure and providers
Supabase, Twilio, configurable model/speech providers, email, and billing paths may process data depending on configuration. Hosting region, transfer mechanism, certifications, and provider contract terms require confirmation.
8. Incidents and reporting
Report suspected security issues to [SECURITY_EMAIL]. Incident response, notification timing, recovery objectives, and support targets are [INCIDENT_NOTIFICATION_PERIOD], [RTO], [RPO], and [SUPPORT_POLICY].
9. Security review
The current package intentionally does not claim ISO, SOC, HIPAA, GDPR certification, sovereign hosting, or a fixed uptime percentage. Those statements require independent evidence and approval.