Security
The following describes controls that are implemented in the product today. We do not claim third-party certifications we have not earned.
Organization isolation
Workspace records are scoped to an organization. Server requests resolve the active tenant before business data is read or written.
Role-based authorization
Capabilities are checked against membership roles so members only see and change what their role allows.
Authentication via Clerk
Sign-in and session management are handled by Clerk. Application secrets stay on the server.
Auditability
Structured logs and correlation IDs support reconstructing what happened and when.
Protected secrets
API keys and service credentials are not exposed to the browser. Downloads and sensitive actions require server-side authorization.
POLCA is not currently SOC 2, ISO 27001, HIPAA, or PCI certified. Compliance programs may be pursued as the product matures.