Credentials stay with connection providers
Portal forms, records, and logs reject high-signal credential values. Uploaded files are malware scanned, not secret-content scanned, so never upload passwords, API keys, recovery codes, or private tokens.
Security model
The onboarding workspace collects the context needed to build and verify an AI employee. It is not a password form, and client activity never self-certifies access or testing.
Portal forms, records, and logs reject high-signal credential values. Uploaded files are malware scanned, not secret-content scanned, so never upload passwords, API keys, recovery codes, or private tokens.
Every client record is protected by organization and engagement membership policies in Postgres. Access is denied unless a signed WorkOS session proves the correct organization context.
OAuth, admin invites, and dedicated service identities are preferred. Scope, purpose, ownership, testing, approval, expiry, and revocation remain visible throughout onboarding.
Files are private, encrypted, type and size constrained, and unavailable until malware scanning passes. Every upload is tied to one engagement and an audit event.