Access boundaries
Organization-scoped RBAC, tenant API keys, service credentials, and backoffice-only platform controls protect privileged paths.
security & trust
This ledger separates shipped controls from optional services and pending assurance work. No implied certification. No hidden trust badge.
technical disclosure · continuously updated
Organization-scoped RBAC, tenant API keys, service credentials, and backoffice-only platform controls protect privileged paths.
Runs, agents, integrations, memories, and usage reporting carry organization scope. Cross-tenant access contracts run in the backend test gate.
Approval gates, audit traces, signed webhooks, rate limits, token quotas, and revocable credentials govern automated work.
service map
Model providers and monitoring are deployment choices. Customer data reaches them only when the corresponding service is configured and used.
Subscription billing and hosted payment flows
Core billing
Runtime exception monitoring when configured
Optional
Model inference selected by the operator
Configurable
Alternative model inference selected by the operator
Configurable
Repository context and approved pull-request automation
Optional integration
assurance evidence
Authenticated routes classified and contract-tested
Cross-organization access denial covered by automated tests
MCP environment values and bearer tokens encrypted separately and omitted from API responses
Operator-only MCP subprocess discovery and execution browser-tested
Database migration head checked by production audit
Dependency vulnerability audit included in release readiness