Account access
Hashed credentials, optional authenticator MFA, device management, short-lived installation tokens, and rotating refresh credentials.
Security and privacy
Implemented controls
Hashed credentials, optional authenticator MFA, device management, short-lived installation tokens, and rotating refresh credentials.
Tenant-scoped APIs and role-based team permissions keep workspace access tied to an authenticated account and approved role.
TLS in transit, rate limits, hardened non-root services, least-privilege service accounts, and security-focused response headers.
SQLite integrity checks, backup procedures, and restore-readiness checks make recoverability an operating requirement rather than a policy sentence.
Security and administrative actions produce audit history so teams can review sensitive changes and access-related events.
Standard tracking sends message metadata rather than message bodies. Stored content and files enter the suite through deliberate product workflows.
Data practice
Assurance status
Use the support contact and include enough detail to reproduce the issue. Do not access other users’ data, disrupt the service, or perform destructive testing. Credible reports are acknowledged and coordinated through remediation and disclosure.