Security and data
Where the data lives, how clients authenticate, what is logged.
Residency and tenancy
The service runs on Render in Frankfurt. Authentication and the database run on Supabase in AWS eu-central-1 (Frankfurt). The workspace is the tenancy boundary: every query filters on it and the database enforces it again with row-level security for the application role. The application refuses to start with a superuser or a role that bypasses row-level security.
Authentication
- Web app: email and password or a sign-in link, with a session cookie. Passwords need at least ten characters.
- AI clients: OAuth 2.1 with PKCE and dynamic client registration against the OIDA authorisation server. Access tokens are short-lived JWTs verified on every request (issuer, audience, asymmetric algorithm, expiry). Membership and role are checked on every call.
- No long-lived API keys. Grants can be reviewed and revoked in Settings → Account.
- Email perimeter: an owner can list the email domains of the organisation in Settings → Team. Invitations, invite acceptance, the web application and every MCP call then require an address from one of those domains, including for existing members.
Research capture and export
Off by default. An owner can enable research capture in Settings → Account after confirming that members have been informed. While it is on, each successful MCP tool call is stored with its full arguments and result (secrets redacted), each resolve_decision_state answer carries a call_id, and members rate answers with the rate_answer tool or on the Answers page. The organisation owns this material: an owner can download the whole workspace, capture included, as gzipped JSON Lines from Settings → Account (audited as workspace.exported).
Hardening
- Server-rendered pages with targeted browser scripts and a nonce-based Content Security Policy. Configured public pages load PostHog only after measurement consent.
- CSRF protection on every cookie-authenticated form. Origin validation and CORS on the bearer surface.
- Parameterised SQL only. Schema-validated environment, tool inputs and forms.
- Body limits and per-user or per-address rate limits on the MCP endpoint and the authentication forms.
- Write tools (ingest, ontology, review, conflicts) are limited per member: 20 calls a minute and 200 a day by default. Ingestion rejects recognised credential patterns; this is not a guarantee that every secret can be detected.
- Evidence and source text returned to an AI client are declared data, never instructions, in the server instructions.
- Logs redact tokens and never contain configuration values.
What is stored
Account email, organisation and workspace names, memberships, the ontology, decision records with their evidence passages and source references, review and audit history and usage records. The submitted source text is stored and included in workspace exports. Upstream changes do not yet retire old evidence automatically. The resolver’s as_of selects effective dates under current governance, not past knowledge. Details on processing and rights are in the privacy policy.
