Encrypted credentials and TLS
Provider and integration credentials use encrypted application fields. Public traffic should be served over HTTPS/TLS at deployment level.
We do not claim column-level encryption for all data or key separation without production-configuration evidence. Cryptographic parameters should be confirmed in environment documentation.
Roles, 2FA, and operation audit
The workspace enforces company membership roles, resource authorisation, invitations, and optional two-factor authentication. Important operations are stored in the audit log.
Permission-review frequency and administrator-access rules are organisational processes. They require procedural evidence, not merely website copy.