Access
Server-resolved organizations and roles
Workspace membership and role authority come from the application database, not a browser-selected identifier.
Security & trust
The current foundation is designed around server authority, workspace isolation, protected credentials, explicit approval, safe diagnostics, and auditable operational actions.
Verified controls
Access
Workspace membership and role authority come from the application database, not a browser-selected identifier.
Isolation
Server authorization and row-level security provide separate layers against cross-workspace access.
Credentials
Client provider credentials are designed for encrypted workspace-scoped storage and redacted diagnostics.
Approval
Draft approval, suppression, caps, quiet hours, and provider restrictions are checked before eligible dispatch.
Administration
Service administration is limited to aggregate evidence and audited operational actions without client content or secrets.
Ownership
The protected owner workspace remains outside normal client billing, deletion, suspension, and migration paths.
Readiness status
Verified visitors can create an isolated workspace and select a plan through authenticated Stripe Checkout. Provider connections and campaign sending remain deliberate, workspace-specific actions: customers supply their own provider credentials, and sending requires setup, review, approval, and the applicable safety checks.
No public statement on this page is a certification, penetration-test report, availability SLA, or guarantee that an incident cannot occur.
Data boundaries