Skip to content

Security

Security boundaries are part of the operating model.

SiteReport is being built around explicit tenant isolation, server-side authorization and traceable human review rather than treating security as launch-day polish.

01

Workspace authorization

Workspace membership and role checks are enforced on the API. Nested resources remain scoped through their authorized workspace and project.

02

Session controls

Short-lived access tokens stay in browser memory while refresh tokens use HttpOnly cookies with rotation and revocation.

03

API hardening

Authentication endpoints are throttled, request validation is deny-by-default, and production HTTP security headers are explicitly configured.

04

Audit and traceability

High-impact product changes emit audit events, while request correlation and AI diagnostics avoid logging complete sensitive source bodies.

05

Human-controlled AI

SiteReport-managed AI, approved customer providers and MCP clients stay behind tenant authorization, validated structured operations, provenance and human-controlled approvals.

06

Controlled external access

Client portals, partner access and secure share links are scoped to explicitly shared resources rather than granting external users normal internal workspace access.

Authorization model

Tenant boundaries are enforced where the data is served.

UI visibility is never treated as authorization. Workspace membership, minimum role and project scope are checked on the API before protected records are returned or changed.

Security model

Authorization stays server-side

Identity

Authenticated user

Short-lived access token + rotated refresh session.

API authorization boundary

Workspace

Membership required

Role

Minimum role enforced

Project

Tenant scope verified

Traceability

Audit high-impact actions

Membership, review and workflow changes retain workspace context.

AI boundary

Human review remains required

AI cannot submit, approve or publish reports autonomously.

Production readiness

Harden what exists. Do not claim what does not.

Production-readiness work is still in progress. SiteReport does not claim certifications or formal compliance attestations that have not been independently established.

Dependency vulnerability and high-confidence secret checks run in CI.

API liveness/readiness and graceful shutdown are validated against PostgreSQL.

Production Swagger exposure is disabled by default.

Binary evidence storage remains a pre-launch gap until a private object-storage path is selected.

Trust questions

The questions security and operations teams usually ask first.

SiteReport documents what is already true and leaves production-provider, certification and residency claims open until they are actually established.

Can a hidden button bypass workspace permissions?

No. Protected records are authorized on the API using workspace membership, role and project/resource scope.

Can AI publish or approve operational records by itself?

No. AI-assisted outputs remain subject to SiteReport validation, authorization and human-controlled lifecycle decisions.

Do client or partner users become normal workspace members?

No. External access is designed as a separate, resource-scoped boundary for explicitly shared information and actions.

Where will production data be hosted?

The final production hosting and data-residency policy will be published after the production infrastructure provider and region strategy are selected.

Does SiteReport claim SOC 2, ISO 27001 or another certification?

Not unless and until the relevant audit or certification has actually been completed and can be substantiated.

How are privacy and cookie choices documented?

The Privacy Policy explains categories, purposes and browser storage. Optional analytics or marketing storage stays off unless configured and permitted.

Current operational probes

GET /api/health/live

Process liveness without optional AI dependencies.

GET /api/health/ready

PostgreSQL-backed readiness with safe failure responses.