Identity and sessions
Server-side authentication, verified email, time-limited single-use recovery links, session revocation, brute-force controls, and role checks protect workspace access.
Server-side authentication, verified email, time-limited single-use recovery links, session revocation, brute-force controls, and role checks protect workspace access.
Integration tokens are sealed at rest, returned redacted, constrained by exact destination allowlists, and never exposed to the browser.
External AI is double-gated. Egress audits record processor, purpose, data categories, item count, result, and time without recording prompts, task content, or transcripts.
Task and integration activity retain actor, state, time, and provider outcome so a requested action is not mistaken for a completed one.
Strict transport security, restrictive content security policy, signed inbound webhooks, bounded requests, replay defenses, rate limits, and fail-closed provider configuration.
Workspace export, connection revocation, consent withdrawal, and authenticated account-deletion requests are available without claiming instant erasure.
Owners, admins, assistants, and members receive explicit server permissions; restricted actions are row-filtered and members can mutate only work they own or created.
On AWS, governed workspace changes and audit intents are saved together with conditional DynamoDB writes. Exports verify a per-workspace SHA-256 chain, and the archiver copies events to S3 Object Lock storage. Owners and admins can export JSON or CSV evidence.
Implemented posture
Not yet claimed
Critical Path does not currently claim SOC 2 or ISO certification, independently tested tenant isolation, provider-accepted SAML SSO/SCIM, customer-managed encryption keys, data residency selection, a contracted SLA, legal hold, or verified production restore objectives. The SSO/SCIM implementation exists but remains disabled until a production provider is configured and accepted.
Report a security or privacy concern to support@quadrant.works. Do not include passwords, tokens, private calendar links, or unredacted workspace content.