Skip to content

Security

Being clear about what is off is part of the posture

This page states the commitments the product is built to, and lists the capabilities that are deliberately not active. Nothing here is a compliance claim or a certification.

Interface previewNo production data exists

Commitments

Least privilege by default

Every role starts with nothing and is granted only what its work requires.

Server side authorisation

Access decisions are never made by hidden interface elements alone.

Scoped profile access

A profile collaborator reaches one profile, optionally for a limited period.

Attributed history

Every meaningful action is recorded with the actor, the surface and the change.

No silent retrieval

The platform does not fetch a remote address or an image on your behalf without an approved review.

Separation of surfaces

Public, Studio, Console and Admin are distinct areas with distinct expectations.

Deliberately not active

CapabilityReason
Remote URL retrievalBlocked until a server side request forgery review is approved.
cURL executionNever implemented. A command is text.
Image download and scanningNot built. No quarantine, no scanner, no cache.
Database and storageNot created in this release.
Operational authenticationInterfaces exist. No session is issued and no credential is accepted.
Email deliveryNo provider is connected, so no invitation or notice can be sent.
PaymentsNo provider is selected or connected.
Identity verificationNo provider is connected. No document can be uploaded.
Public API and MCPNot activated.

Reporting a concern

A coordinated disclosure process will be published with the first operational release. Until then, use the contact page. Please do not send sensitive material.

The importer page explains upload handling in more detail.

How the importer treats data