Team access
Use individual verified identities and mandatory authenticator verification for the console. Keep a verified backup authenticator on a separate device. In Account security you can replace a device after proving the replacement, leave projects, or as owner request irreversible project erasure by typing its exact name. Access freezes first; bounded database removal and queued private-storage cleanup have a retained progress receipt. Outstanding billing, deliveries and uncertain uploads must be reconciled first. You can also request deletion of your login when enabled. Transfer sole ownership before leaving. Login deletion preserves company-owned records; it does not erase every project or backup. Review team roles regularly.
Two-factor authentication
Enroll an authenticator from Account security. Techrace operator access additionally requires an explicit operator-user configuration and an AAL2 session; company owner/admin roles do not bypass it.
Credential storage
Provider tokens and queued email/advertising payloads use versioned encryption with tenant context. Project API keys are hashed. Server keys belong in your secret manager, not customer browsers.
Revocation
Rotate or revoke API keys, disconnect unused provider accounts and revoke consent at the provider. Keep your own application’s customer authorization checks in place on every request.
Operational assurance
Independent penetration tests, hosted workload validation, monitoring and recovery drills are launch requirements. No SOC2/ISO certification or production SLA is claimed.
These guides describe implemented code and operating requirements. Enabled capabilities and permissions may differ. Use the current API specification and your project’s capability view.
OpenAPI specification