Skip to content

Security & trust

Protect the work. Minimize the exhaust.

Critical Path is designed around explicit authority, content minimization, observable external actions, and fail-closed integrations. This page distinguishes implemented controls from enterprise capabilities still in progress.

Identity and sessions

Server-side authentication, verified email, time-limited single-use recovery links, session revocation, brute-force controls, and role checks protect workspace access.

Credential boundaries

Integration tokens are sealed at rest, returned redacted, constrained by exact destination allowlists, and never exposed to the browser.

Content-minimized egress

External AI is double-gated. Egress audits record processor, purpose, data categories, item count, result, and time without recording prompts, task content, or transcripts.

Inspectable actions

Task and integration activity retain actor, state, time, and provider outcome so a requested action is not mistaken for a completed one.

Secure delivery

Strict transport security, restrictive content security policy, signed inbound webhooks, bounded requests, replay defenses, rate limits, and fail-closed provider configuration.

User control

Workspace export, connection revocation, consent withdrawal, and authenticated account-deletion requests are available without claiming instant erasure.

Fine-grained authorization

Owners, admins, assistants, and members receive explicit server permissions; restricted actions are row-filtered and members can mutate only work they own or created.

Tamper-evident audit

On AWS, governed workspace changes and audit intents are saved together with conditional DynamoDB writes. Exports verify a per-workspace SHA-256 chain, and the archiver copies events to S3 Object Lock storage. Owners and admins can export JSON or CSV evidence.

Implemented posture

No trust by implication

  • External AI is disabled by default and task mutation requires confirmation.
  • WhatsApp message bodies are processed transiently, not stored in workspace records.
  • Slack and WhatsApp credentials remain server-side and destinations are scoped.
  • AWS audit writes use conditional transactions and chain verification. An asynchronous archiver writes S3 Object Lock copies; live DynamoDB records remain mutable by privileged roles.

Not yet claimed

Evidence before badges

Critical Path does not currently claim SOC 2 or ISO certification, independently tested tenant isolation, provider-accepted SAML SSO/SCIM, customer-managed encryption keys, data residency selection, a contracted SLA, legal hold, or verified production restore objectives. The SSO/SCIM implementation exists but remains disabled until a production provider is configured and accepted.

Report a security or privacy concern to support@quadrant.works. Do not include passwords, tokens, private calendar links, or unredacted workspace content.