Skip to main content

Security

Connect product data without giving up control.

Shiptawk is built around explicit source access, server-enforced workspace authorization, bounded public contracts, evidence-backed actions, and human approval.

Security overview reviewed 31 July 2026. Contact Pillardash for architecture or procurement questions.

Access

Every source connection has a visible boundary.

  • You choose every connected repository
  • Repository monitoring requires explicit opt-in
  • You select the Search Console property
  • Provider access can be revoked
  • Sign-in does not grant source access
  • Server operations enforce workspace context
Section 1

Credentials and contracts

Secrets stay behind server-owned boundaries.

  • Provider credentials are encrypted at rest
  • Credentials are excluded from public API responses
  • Browser-facing contracts expose bounded projections
  • Provider scopes are purpose-specific
  • Refresh and revocation state is tracked
  • Credentials and private source are not logged
Section 2

Workspace isolation

Ownership is checked where the operation happens.

01

Tenant scope

Product and source operations require authoritative workspace context.

02

Aggregate scope

Relationships are validated so one product cannot reference another product’s source accidentally.

03

Actor attribution

Who performed an action remains distinct from which workspace owns the data.

04

Negative tests

Cross-workspace access paths are covered by authorization tests.

Section 3

Responsible AI

Generation is not an authority boundary.

  • Recommendations use approved product context
  • Public claims require linked evidence
  • Insufficient evidence can produce no recommendation
  • Structured output is validated before domain use
  • Restricted topics and sensitive data remain bounded
  • Historical runs preserve prompt and source provenance without exposing secrets
Section 4

Public actions

Nothing becomes public simply because a model generated it.

Generated customer-facing work remains private until the configured approval is recorded for the exact revision.

Section 5

Have a security or procurement question?

Use the Pillardash contact route to discuss source access, architecture, or deployment questions.

Separate source consent. Optional GitHub evidence. Approval before publication.