Envelope encryption
Every key is sealed with a per-business AES-256 data key, itself encrypted by a master key held in a separate, self-hosted vault (Infisical). A database breach yields ciphertext.
Row-level security, enforced at boot
Per-company isolation is enforced in the database. The API checks the policy on startup and refuses to boot if it is not enforced.
Keycloak SSO, server-side login
OIDC with Google sign-in. Access tokens live in memory, never in URLs; silent refresh; 30-minute inactivity logout; tokens bound to the API they were issued for.
One key, one task
Each agent receives only the credential its task needs — never a global key. Credentials are never written to logs, error messages or the knowledge base.
CSP, HSTS, CSRF, rate limits
Strict per-request CSP and HSTS. CSRF protection and IDOR test suites across the API. Founder task text is fenced before it reaches GitLab.
Append-only, on every write
Tasks, wiki edits, CRM records, CEO actions and credential use are recorded with timestamp, actor and purpose.
Agents that can't hurt you by accident.
- Never push to
main. Work arrives as merge requests. - Sensitive paths always need a human — auth, secrets, payments, migrations, access control, dependency manifests.
- QA and Security are read-only agents. They report; they don't patch.
- Per-company containers, non-root, no Docker socket.
- Your Claude credential never touches the platform — the team is authorised through a paste-a-code relay.
- The MCP server holds no credential and cannot approve anything.
pipelinegreenQA-GATEPASS · 2781 testsSECURITY-GATEPASSpathsbilling/ → HELD for founderauto-mergedeclined · human review required
Authority is a document.
The CEO's limits are written down, readable over MCP (ceo_authority_get) and editable only in the cabinet. A proposal above the line is queued, and a queued proposal has not happened.
Honest boundaries.
Are you GDPR / HIPAA / PCI / SOC 2 certified?
Where do backups live?
Are the legal documents final?
Has a third party audited the platform?
Questions? Ask us directly.
Security questionnaires, architecture reviews, DPA — email and a human answers.