Trust starts with clarity.
The public website is static. It does not accept passwords, API keys, private documents or payments. The member product runs in an invite-only private beta, where councils currently use simulated provider responses.
Account access
Private staging uses Auth0 sign-in, server-side sessions and invitation checks. The owner can sign in now through a private link. The public member URL is undergoing deployment review, so login buttons on this website remain inactive.
Provider credentials
The private build encrypts submitted API keys with a public key. Only the council worker holds the private key needed to open them. Tests use fixture credentials; real provider connections have not yet been validated.
Spending controls
The build reserves a bounded amount before a council starts and tracks uncertain charges conservatively. Independent review and live-provider verification are ongoing. Paid use is not active.
Workspace isolation
Each workspace’s councils, sources and records are separated in the database itself, using row-level security that is tested directly, not only through the app. Deleting a workspace removes its content from the live database right away and keeps a billing record of model charges (amounts, model names and times, no content) so spending limits stay accurate. Encrypted backups may still hold deleted content until they rotate out; backup retention will be documented in the member privacy notice before invitations open.
Network access
Today the private council worker has no internet access at all. When live providers are connected, its outbound traffic will be limited to the official provider API addresses through an allowlisting proxy that does not decrypt traffic. That proxy is built and tested but not yet switched on.
What this does not promise
No system is immune to compromise. Worker or host compromise can expose credentials in use. We do not claim a security certification, completed independent penetration test or production readiness.
Reporting a concern
Report a security concern to [email protected]. Describe the issue without including passwords, API keys or other secrets, and do not send personal data through the public demo.