Identity and multi-factor authentication
OIDC authorization-code flow with PKCE, nonce and state validation, verified-email enforcement, opaque server-side sessions, and signed multi-factor authentication evidence required in production.
This page distinguishes controls already implemented in the application from operational work that must be completed before general availability.
OIDC authorization-code flow with PKCE, nonce and state validation, verified-email enforcement, opaque server-side sessions, and signed multi-factor authentication evidence required in production.
Organization membership, role-based permissions, tenant-scoped repositories, PostgreSQL row-level security, and explicit approval boundaries.
Source audio and transcripts are processed transiently. Structured history is retained for 30 days by default. OAuth credentials are encrypted, and HTTPS plus restrictive browser security headers are enforced.
Payment details are collected on Stripe-hosted pages, webhooks are signed and idempotent, prices are selected server-side, and entitlements are enforced at organization level.
Report suspected vulnerabilities privately to brianalam81@gmail.com. Do not include real customer data unless requested through a secure channel.