Website controls
The site is served over HTTPS. Its Worker sets a Content Security Policy that restricts scripts and styles to first-party sources, disallows embedded objects, and prevents framing. Response headers also disable MIME sniffing and restrict browser access to camera, microphone, and geolocation.
DNSSEC is enabled for the domain. The workflow explorer runs in the browser with sample data and holds no ERP credentials. Contact and support forms are intended for non-sensitive inquiries.
Integration security requirements
Review authentication, role management, credential storage, tenant boundaries, encryption, logging, and incident responsibilities for the intended deployment. Match each requirement to an implementation and the evidence needed to assess it.
- Scope contracts, connections, inputs, runs, and receipts to the customer and company identity.
- Authorize only the reads and actions required by the task contract.
- Treat documents and model output as untrusted data, not a source of new permissions.
- Keep model routing within configured data boundaries and approved processing destinations.
- Exclude credentials and unnecessary document contents from operational evidence.
Security review
Review the deployment and data flow for your workload. Identify which providers can receive which fields, how destination credentials are scoped and rotated, how authorization is checked during retries, and which records support an investigation after an uncertain write.
Bring requirements for access reviews, independent testing, recovery, vulnerability management, and subprocessors to the technical discussion. For each requirement, identify the responsible party, assessment scope, and supporting evidence.
Reporting a suspected security issue
Use the support contact page to identify a security concern and provide the affected URL, a concise description, and non-sensitive reproduction information. Do not include production secrets, personal records, or exploit payloads in the initial message. The team can coordinate an appropriate channel for additional detail.
If you believe a credential has been exposed, revoke it through the system that issued it. Keep testing within systems and accounts you are authorized to assess, and include only the minimum information needed to reproduce a suspected issue.
Missing a detail or found a problem?
Send a documentation question →