Security
Being clear about what is off is part of the posture
This page states the commitments the product is built to, and lists the capabilities that are deliberately not active. Nothing here is a compliance claim or a certification.
Commitments
Least privilege by default
Every role starts with nothing and is granted only what its work requires.
Server side authorisation
Access decisions are never made by hidden interface elements alone.
Scoped profile access
A profile collaborator reaches one profile, optionally for a limited period.
Attributed history
Every meaningful action is recorded with the actor, the surface and the change.
No silent retrieval
The platform does not fetch a remote address or an image on your behalf without an approved review.
Separation of surfaces
Public, Studio, Console and Admin are distinct areas with distinct expectations.
Deliberately not active
| Capability | Reason |
|---|---|
| Remote URL retrieval | Blocked until a server side request forgery review is approved. |
| cURL execution | Never implemented. A command is text. |
| Image download and scanning | Not built. No quarantine, no scanner, no cache. |
| Database and storage | Not created in this release. |
| Operational authentication | Interfaces exist. No session is issued and no credential is accepted. |
| Email delivery | No provider is connected, so no invitation or notice can be sent. |
| Payments | No provider is selected or connected. |
| Identity verification | No provider is connected. No document can be uploaded. |
| Public API and MCP | Not activated. |
Reporting a concern
The importer page explains upload handling in more detail.
How the importer treats data