Private betaRequest access

Security

Access is scoped before context is assembled.

This page describes implemented product boundaries and operating practices without claiming certifications or guarantees that have not been documented.

01

Authentication

Server-side sessions protect browser routes. Mutations use CSRF protection, and accounts or organizations can be suspended.

02

Tenant isolation

Private queries are scoped by owner and organization. MCP uses one validated active organization with server-side membership checks.

03

Provider boundary

Only selected context is sent. Provider keys remain server-side; models do not receive database credentials.

04

Review + authorization

Important proposals remain reviewable. Sensitive Operator approvals are scoped to a single owner and run.

Restricted capabilities

Models do not receive unrestricted system access.

× No unrestricted shell access× No unrestricted filesystem access× No arbitrary repository mutation× No deployment access× No browser automation access× No credentials or database connections

Data operations

Inspectable records and bounded logs.

ReasonTrail preserves failed runs, verification evidence, approvals, and audit history for diagnosis.

PostgreSQL storageBackupsJSON exportsMarkdown exportsAudit eventsBounded, redacted logs