Access
Workspace access and connected assets are limited to authorized users and scoped operational roles.
Transport
Public service traffic uses HTTPS, and integration secrets are kept separate from public configuration.
Isolation
Workspace and channel context are kept distinct so one customer workflow does not become another’s context.
Validation
Webhook signatures, authorization state, request shape, and policy conditions are checked before protected actions.
Visibility
Operational events and delivery state support troubleshooting, accountability, and abuse investigation.
Lifecycle
Access can be revoked, integrations disconnected, and eligible data deleted through documented controls.
Responsible reporting
Found a security issue?
Do not expose customer data, credentials, or live platform tokens in a report. Use the secure support channel already established for your workspace or service relationship, include clear reproduction steps, and allow time for investigation before public disclosure.