Skip to content
All documentation

Trust and safety

Security, privacy, and trust boundaries

The security model clients and operators should understand, including identity, tenancy, permissions, uploads, secrets, webhooks, audit history, and destructive operations.

13 minute readClient · Founder · Operator · Engineer

Identity and tenant isolation

Sufrone Operations users and Sufrone Client Workspace users operate through different authorization boundaries. Client access resolves to a client identity and effective workspace capabilities. Administrative actions require explicit permissions rather than trusting a visible role label alone.

Tenant-scoped reads and writes must resolve the owning client before returning or changing data. A route being difficult to guess is not treated as access control.

High-trust actions

  • Founder approval of an exact proposal version.
  • Payment approval and allocation.
  • Role and permission management.
  • Release promotion and production changes.
  • Archiving or destructive maintenance affecting client records.
  • Security configuration and secret rotation.

Evidence and retention

Audit history records who performed a controlled action, when it happened, and the relevant identifiers or fingerprints. Sensitive secrets are referenced rather than copied into ordinary notes. Client records are archived rather than casually deleted, and destructive maintenance requires an explicit database-level approval boundary.

Uploads and provider events

Private uploads are subject to type, size, quota, and access controls. Provider webhooks are verified, stored idempotently, and reconciled rather than trusted merely because they reached a public endpoint. Retention workers remove evidence only according to an explicit policy.