Workspace authorization
Workspace membership and role checks are enforced on the API. Nested resources remain scoped through their authorized workspace and project.
Security
SiteReport is being built around explicit tenant isolation, server-side authorization and traceable human review rather than treating security as launch-day polish.
Workspace membership and role checks are enforced on the API. Nested resources remain scoped through their authorized workspace and project.
Short-lived access tokens stay in browser memory while refresh tokens use HttpOnly cookies with rotation and revocation.
Authentication endpoints are throttled, request validation is deny-by-default, and production HTTP security headers are explicitly configured.
High-impact product changes emit audit events, while request correlation and AI diagnostics avoid logging complete sensitive source bodies.
SiteReport-managed AI, approved customer providers and MCP clients stay behind tenant authorization, validated structured operations, provenance and human-controlled approvals.
Client portals, partner access and secure share links are scoped to explicitly shared resources rather than granting external users normal internal workspace access.
Production readiness
Production-readiness work is still in progress. SiteReport does not claim certifications or formal compliance attestations that have not been independently established.
Dependency vulnerability and high-confidence secret checks run in CI.
API liveness/readiness and graceful shutdown are validated against PostgreSQL.
Production Swagger exposure is disabled by default.
Binary evidence storage remains a pre-launch gap until a private object-storage path is selected.
Trust questions
SiteReport documents what is already true and leaves production-provider, certification and residency claims open until they are actually established.
No. Protected records are authorized on the API using workspace membership, role and project/resource scope.
No. AI-assisted outputs remain subject to SiteReport validation, authorization and human-controlled lifecycle decisions.
No. External access is designed as a separate, resource-scoped boundary for explicitly shared information and actions.
The final production hosting and data-residency policy will be published after the production infrastructure provider and region strategy are selected.
Not unless and until the relevant audit or certification has actually been completed and can be substantiated.
The Privacy Policy explains categories, purposes and browser storage. Optional analytics or marketing storage stays off unless configured and permitted.
Privacy & legal
GET /api/health/live
Process liveness without optional AI dependencies.
GET /api/health/ready
PostgreSQL-backed readiness with safe failure responses.