Skip to content
techrace/
TRUST / SECURITY

Security is part of the connection

These are implemented controls and operating requirements, not a certification or a promise of zero risk.

Customer boundaries

Every connection belongs to a developer project and downstream customer. API keys are scoped to a project, membership and allowed operations. Database row security restricts direct browser access.

Credentials and data

Provider credentials and queued email payloads are encrypted with AES-GCM using tenant-bound context and versioned keys. Tokens and mail bodies are not included in application error logs. Mail reads are returned to the authorized caller, not indexed for general search.

Actions and recovery

Background actions use durable records, bounded retries and fenced leases. Uncertain mail sends are marked ambiguous instead of being blindly resent. Hosted load tests, penetration tests and recovery drills are required before production rollout.

Report a security concern

The production security contact and disclosure workflow will be published once the operating company and domain are confirmed. Production onboarding requires these details to be configured.

Platform review guide