Security

The following describes controls that are implemented in the product today. We do not claim third-party certifications we have not earned.

  • Organization isolation

    Workspace records are scoped to an organization. Server requests resolve the active tenant before business data is read or written.

  • Role-based authorization

    Capabilities are checked against membership roles so members only see and change what their role allows.

  • Authentication via Clerk

    Sign-in and session management are handled by Clerk. Application secrets stay on the server.

  • Auditability

    Structured logs and correlation IDs support reconstructing what happened and when.

  • Protected secrets

    API keys and service credentials are not exposed to the browser. Downloads and sensitive actions require server-side authorization.

POLCA is not currently SOC 2, ISO 27001, HIPAA, or PCI certified. Compliance programs may be pursued as the product matures.