Contents
Data & token security
A short summary — the full breakdown lives on the security page.
- Encrypted tokens. OAuth access and refresh tokens for every connected account are encrypted at rest (AES-GCM) and are never sent to your browser.
- Hardened OAuth. Every connection flow is bound to a random, server-side, one-time state value tied to your account — never trusted from the client — plus PKCE, closing CSRF and token-injection attacks.
- Per-workspace data isolation. Every request is authenticated and every read or write is scoped to your workspace; membership and ownership are re-checked server-side before any mutation.
Full detail, including how to report a security issue, is on the Security page.