Security

The application runs on Cloudflare Workers with data in the deployment’s configured store. Sessions use signed cookies; passkeys are supported where enabled.

Staff and coach access to customer workspaces exists only when your service model includes it, and is disclosed on those sales pages and in-product.

Secrets and vendor credentials are never exposed to browsers. Integration health is fail-closed for missing configuration.