Security, privacy, and governance
Tenant isolation
Every request is bound to an Organization, Tenant, and Workspace. Resource IDs are never sufficient authorization. Provider, dashboard, tracking, privacy, report and action operations verify Workspace ownership.
Secrets
- Store provider API keys encrypted or reference deployment secrets.
- Never place provider keys, platform API keys or tracking write tokens in URLs, logs, dashboard exports or browser storage.
- Browser tracking uses a dedicated scoped site token, not a platform API key.
- Rotate and revoke credentials; do not reuse one key across unrelated workspaces.
Outbound safety
Provider and channel destinations require valid URLs. HTTPS is the default. Private-network and insecure HTTP access require explicit deployment policy. Resolve and validate destinations to reduce SSRF risk; use host allowlists for publishing.
Trust boundaries
Browser tracking tokens cannot call platform APIs. Platform API keys and provider/channel credentials must never be shipped to the browser.
Privacy
Tracking is pseudonymous by default, honors supplied consent state, sanitizes URLs and applies configured retention. Data-subject access/delete requests are scoped to the site and workspace. Raw response retention should be disabled unless a documented purpose and retention period exist.
Governance and audit
Configuration changes, provider lifecycle, dashboard definitions, schedules, approvals, actions, publication, rollback and privacy work produce audit events. Action events are immutable. High-risk external mutations require policy and approval before execution.
Tenant administrators can review Tenant Activity to filter audit events by user or system actor, Workspace, operation, and entity. This is an audit view; it does not expose provider credentials, raw secrets, or cross-Tenant activity.
Roles and operational access
Manage Tenant team membership separately from Workspace access. Apply least privilege to owners, administrators and members. Use two-factor authentication for privileged users and review Tenant Activity regularly.
Control matrix
| Risk | Required control | Verification |
|---|---|---|
| Cross-tenant data access | Organization/Tenant/Workspace ownership on every operation | Negative tenant tests and audit review |
| Credential disclosure | Encrypted value or secret reference; server-side resolution and redaction | Browser bundle, log and export scans |
| SSRF/private-network access | HTTPS, DNS/IP validation, allowlists and explicit dev-only overrides | Loopback/private/link-local test cases |
| Unauthorized publication | Capability, policy, approval, idempotency and destination scope | Rejected and expired approval tests |
| Tracking privacy breach | Site token, allowed origins, consent, sanitization, retention and DSAR | Consent/origin/retention/privacy tests |
| Misleading metrics | Version, denominator, sample, confidence and evidence | Metric contract and low-sample tests |
| Uncontrolled automation | Suggest default, budgets, checkpoints, safe stop and emergency stop | Autopilot policy and stop tests |