Skip to main content

Security

How your projects, data and published sites are protected.

Account and access

Accounts use email verification and password sign-in, and sessions expire. Only people you invite to a workspace can open its projects.

Access rules are enforced on the server for every table and file, not in the browser.

Project isolation

Each project has its own Brain. Knowledge, documents, conversations and files are never shared between projects or workspaces.

Previews run in an isolated sandbox that cannot reach your account or other projects.

Data handling

Credentials and assistant transcripts are encrypted at rest, and secrets are never returned to the browser.

Build and publish operations are recorded so a change can always be traced and reversed.

Reporting a problem

If you believe you have found a vulnerability, email support and we will respond with a diagnostic reference.