Server-side access checks
Client identifiers are not treated as proof of access. Requests are authenticated and scoped on the server.
The repository supports specific engineering claims. This page does not imply certification, a completed external penetration test, an uptime promise or a data-residency guarantee.
Client identifiers are not treated as proof of access. Requests are authenticated and scoped on the server.
Tenant records are protected with row-level security rather than application filtering alone.
Payment, communications and AI-provider events include signature verification and safe retry handling.
Administrative privileges are modelled separately, authorised individually and designed for auditable actions.
These omissions are intentional until direct evidence and approval exist.
This form routes to trust@chatursystems.com. Provide only the detail needed to understand the issue; do not include credentials or customer data.
Read the legal security draft