Company
Security first
Security posture
Controls in place for private beta
Identity and access
OAuth-based authorization model with scoped permissions, intended to limit access to only what each integration needs.
Data minimization
The marketing app stores only waitlist-related fields needed for beta communication and qualification.
Input validation
The waitlist API validates email and audience type, and sanitizes optional text inputs before processing.
Operational hardening
Security controls are being iterated during beta, including logging hygiene and deployment posture reviews.
Responsible disclosure guidelines
- If you discover a vulnerability, please contact the team before public disclosure.
- Include reproduction steps, impact assessment, and affected endpoint/page where possible.
- We triage reports based on severity and exploitability and prioritize fixes accordingly.