Authentication and isolation
Google handles sign-in. The app uses HttpOnly, Secure, host-only session cookies in hosted environments, CSRF checks on writes and workspace authorization before record or file access. Public and staging/app hosts do not share login cookies.
Private files and processing
Documents are kept in private Cloudflare R2 storage; workspace metadata uses D1. Native PDF processing runs in an isolated container without outbound internet. Originals and generated copies stay separate. Supported-format, size and resource bounds apply.
Review and recovery
Preview important changes, retain document revisions and use protected backup export/restore. A saved approval, message or payment record is evidence entered by a user, not an external action performed by the system.
What this does not certify
No SOC 2, ISO 27001, regulated-industry certification, enterprise SSO, legal signature validation or service-level guarantee is asserted. Raster-copy redaction has different behavior from preserving an original editable PDF. Read each tool report.
Assistant access and public assets
Hosted assistant connections are in preview. Scoped authorization can expose saved records and optional draft creation to compatible MCP clients. End-to-end ChatGPT and Claude acceptance is still pending; no directory approval is claimed. Authorizing a connection can share requested workspace information with your chosen assistant. Revoke access in settings. BYOK and managed chat are not enabled. Fonts and artwork are self-hosted; no marketing analytics SDK is included.