Security
This page describes the safeguards Architect has in place today. We keep it factual: if something isn't listed here, don't assume we offer it.
Workspace isolation
Each workspace's data is separated in the database itself. Row-level security policies tie every read and write to workspace membership, so a signed-in user can only reach the workspaces they belong to.
Access and roles
- Sign in with an email and password or with Google. Password reset is handled by email.
- Workspace owners invite teammates as Admins, Members or Viewers, and can change or remove access.
Files
Files attached to Entries are kept in private storage. Downloads go through short-lived signed links that are issued only to members of the workspace.
Connected Google accounts
- Gmail, Google Calendar and Google Contacts connect through Google's own consent screen. Calendar and Contacts are read-only.
- The tokens Google issues are stored encrypted (AES-256-GCM) on the server.
- You can disconnect a Google account from Settings at any time.
Architect and AI
Architect proposes changes; it doesn't apply them. Every change to your Blueprint is shown for review and waits for approval. When you use AI features, the content needed to respond is sent to OpenAI, as described in the Privacy Policy. The public demo runs in your browser and doesn't use an AI model.
Certifications
Architect doesn't currently hold third-party security certifications such as SOC 2 or ISO 27001. We'll say so here if that changes.