TENANT ISOLATION
Postgres Row Level Security scopes workspace-owned records to authenticated membership.
SECURITY MODEL
The Console is designed around constrained authority, tenant isolation, verifiable state transitions and honest failure handling.
Postgres Row Level Security scopes workspace-owned records to authenticated membership.
OAuth grants are encrypted server-side with authenticated AES-256-GCM and context binding.
Only allowlisted providers, hosts, scopes and tool identifiers can cross the connector boundary.
Commands persist first; verified provider webhooks record terminal status and usage.
Consequential work pauses with exact impact and a one-time human decision.
Missing secrets and unavailable integrations produce explicit errors, never simulated success.
The system assumes connected data can be adversarial. Tool output is treated as untrusted data, authorization headers are redacted from evidence, outbound endpoints are allowlisted and private network destinations are rejected.
No connector beyond the private NAVINES NOISE developer integration is available. NOISE access itself requires separate developer authorization. Destructive tools are not enabled, and cost figures are estimates rather than billing records.
Security reports can be sent through the contact form. Do not include live credentials, personal data or exploit payloads that affect systems you do not own.