Skip to main content

Security, privacy, and governance

Tenant isolation​

Every request is bound to an Organization, Tenant, and Workspace. Resource IDs are never sufficient authorization. Provider, dashboard, tracking, privacy, report and action operations verify Workspace ownership.

Secrets​

  • Store provider API keys encrypted or reference deployment secrets.
  • Never place provider keys, platform API keys or tracking write tokens in URLs, logs, dashboard exports or browser storage.
  • Browser tracking uses a dedicated scoped site token, not a platform API key.
  • Rotate and revoke credentials; do not reuse one key across unrelated workspaces.

Outbound safety​

Provider and channel destinations require valid URLs. HTTPS is the default. Private-network and insecure HTTP access require explicit deployment policy. Resolve and validate destinations to reduce SSRF risk; use host allowlists for publishing.

Trust boundaries​

Browser tracking tokens cannot call platform APIs. Platform API keys and provider/channel credentials must never be shipped to the browser.

Privacy​

Tracking is pseudonymous by default, honors supplied consent state, sanitizes URLs and applies configured retention. Data-subject access/delete requests are scoped to the site and workspace. Raw response retention should be disabled unless a documented purpose and retention period exist.

Governance and audit​

Configuration changes, provider lifecycle, dashboard definitions, schedules, approvals, actions, publication, rollback and privacy work produce audit events. Action events are immutable. High-risk external mutations require policy and approval before execution.

Tenant administrators can review Tenant Activity to filter audit events by user or system actor, Workspace, operation, and entity. This is an audit view; it does not expose provider credentials, raw secrets, or cross-Tenant activity.

Roles and operational access​

Manage Tenant team membership separately from Workspace access. Apply least privilege to owners, administrators and members. Use two-factor authentication for privileged users and review Tenant Activity regularly.

Control matrix​

RiskRequired controlVerification
Cross-tenant data accessOrganization/Tenant/Workspace ownership on every operationNegative tenant tests and audit review
Credential disclosureEncrypted value or secret reference; server-side resolution and redactionBrowser bundle, log and export scans
SSRF/private-network accessHTTPS, DNS/IP validation, allowlists and explicit dev-only overridesLoopback/private/link-local test cases
Unauthorized publicationCapability, policy, approval, idempotency and destination scopeRejected and expired approval tests
Tracking privacy breachSite token, allowed origins, consent, sanitization, retention and DSARConsent/origin/retention/privacy tests
Misleading metricsVersion, denominator, sample, confidence and evidenceMetric contract and low-sample tests
Uncontrolled automationSuggest default, budgets, checkpoints, safe stop and emergency stopAutopilot policy and stop tests