Workspace-scoped access
Server-side membership and permissions protect business operations. Explicit workspace filters and PostgreSQL row-level security form separate layers; a workspace ID from the browser is not authority.
Understand the controls, their boundaries and what still needs operational verification. No invented certifications. No blanket compliance promises.
Build my email planServer-side membership and permissions protect business operations. Explicit workspace filters and PostgreSQL row-level security form separate layers; a workspace ID from the browser is not authority.
Customer owners are not automatically platform operators. Operator access uses a separate allowlist and authentication policy, with auditable administrative operations.
Workspace integration secrets are encrypted with workspace-bound authenticated encryption. API keys are stored as hashes. Runtime keys, backups and host access still need secure operator management.
Approval, workspace pause, recipient eligibility, suppression and budget are rechecked before submission. A send with an uncertain provider outcome must not be blindly retried.
AI produces structured proposals, not unrestricted SQL or direct send authority. External processing depends on a configured authorized provider and its actual contractual and retention terms.
Export and deletion workflows require authorized access. Audit and suppression records need deliberate retention rules; a deletion request is not a promise that all legal retention obligations disappear.
The operator must verify TLS, backup restoration, key custody, access reviews, provider webhook authentication, incident response and deletion procedures in the deployed environment. Hosting location alone does not establish where every subprocessor handles data.
Create your workspace. Connect your context. Review before you send.