Tenant isolation
Every operational record is scoped to a workspace, with authorization enforced server-side.
Operon is designed around tenant isolation, encrypted connector credentials, audit logs, validation gates, and human approval before sensitive outputs.
Every operational record is scoped to a workspace, with authorization enforced server-side.
Signup, privacy acceptance, workflow transitions, review actions, and output deliveries are logged.
Validation failures and low-confidence AI outputs route to review before downstream action.
Connector and output secrets are stored server-side, encrypted when an encryption key is configured, and excluded from customer diagnostics and exports.
Background processing endpoints support worker-secret authorization for workflow jobs, connector polling, and output delivery retries.
Application responses include security headers for framing, content type sniffing, referrer policy, permissions policy, and a restrictive content security policy.