Security & privacy
Boundaries are part of the product.
Administration Sessions, Tenant API Keys, Hosted credentials, and login proofs are separate credential families.
Core controls
- Tenant ownership is rechecked from authoritative storage.
- One-time credentials are hash-only; provider credentials use encrypted storage.
- Webhook destinations are screened against SSRF and DNS-rebinding risks.
- Guest PII follows a fixed 24-month retention period; workflow credentials expire sooner.
- Tenant deletion has a 30-day grace period and never silently abandons external cleanup.
Operational logs and metrics use safe identifiers and do not use Guest email, Metadata, tokens, or secrets as dimensions.