Trust and safety
Security, privacy, and trust boundaries
The security model clients and operators should understand, including identity, tenancy, permissions, uploads, secrets, webhooks, audit history, and destructive operations.
Identity and tenant isolation
Sufrone Operations users and Sufrone Client Workspace users operate through different authorization boundaries. Client access resolves to a client identity and effective workspace capabilities. Administrative actions require explicit permissions rather than trusting a visible role label alone.
Tenant-scoped reads and writes must resolve the owning client before returning or changing data. A route being difficult to guess is not treated as access control.
High-trust actions
- Founder approval of an exact proposal version.
- Payment approval and allocation.
- Role and permission management.
- Release promotion and production changes.
- Archiving or destructive maintenance affecting client records.
- Security configuration and secret rotation.
Evidence and retention
Audit history records who performed a controlled action, when it happened, and the relevant identifiers or fingerprints. Sensitive secrets are referenced rather than copied into ordinary notes. Client records are archived rather than casually deleted, and destructive maintenance requires an explicit database-level approval boundary.
Uploads and provider events
Private uploads are subject to type, size, quota, and access controls. Provider webhooks are verified, stored idempotently, and reconciled rather than trusted merely because they reached a public endpoint. Retention workers remove evidence only according to an explicit policy.
