Skip to contentleitvik

Documentation

Security and privacy

A summary for reviewers and security teams. The privacy policy and the data processing agreement are the binding documents.

Workspace isolation

  • Each workspace's records are protected by PostgreSQL row-level security that is forced, so not even the table owner bypasses it.
  • Every request binds the workspace and checks current membership again inside the database transaction.
  • A credential belongs to one workspace. A record in another workspace answers 404.

Credentials

  • API tokens are stored only as a SHA-256 hash; the value is shown once.
  • OAuth access tokens (one hour) and refresh tokens (30 days) are opaque and stored as SHA-256 digests. Each refresh rotates the token; reusing an old one revokes the whole family.
  • OAuth uses the authorization code with PKCE S256 only. Only owners and admins can authorize, after a recent sign-in, and consent is never remembered silently.

Revocation

  • Revoke an API token in Settings > API tokens; access ends at once.
  • Disconnecting an application revokes its grant, its access and refresh tokens and the stored consent.
  • Removing a member revokes the connections they authorized; demoting them to member stops those connections at once.
  • Signing out does not disconnect an assistant: revoke it explicitly.

Least privilege

  • Read-only by default. Write tools need writing enabled on the service and a write scope on the credential.
  • No tool sends email or messages, charges, invites people, manages tokens or deletes records.
  • CRM text is returned as untrusted data, with a notice telling the assistant it is never instructions.

Audit trail

  • A token or OAuth connection acts as itself, never as the member who created it. Its writes are recorded with its own identity.
  • Task and opportunity changes keep before and after snapshots; task changes keep the reason.
  • Pasted notes become a proposal that is applied only at the reviewed revision, and the replaced next step can be restored.

Where the data lives

The CRM database is hosted in Frankfurt, Germany (EU). The privacy policy lists the other providers involved and the safeguards for any transfer.

Documents

Report a security issue

Write to hello@pharosyne.tech. Please do not include real customer data in the report.