Security boundary

Connect accounts. Never surrender passwords.

Synquestra is being built as a controlled publishing system—not a browser bot, credential-sharing tool or shortcut around provider review.

Official OAuth only

Provider connections use approved OAuth flows and minimum required scopes. Traditional login automation is excluded.

Tokens stay server-side

Access and refresh tokens must never be placed in browser storage or exposed through frontend variables.

Dedicated data boundary

Synquestra uses its own database. RAQOZ, CostGrid and external workspaces do not share product databases.

Least privilege

Workspace and brand membership narrow what a user can connect, approve, publish or analyse.

Human-controlled release

Maker-checker can prevent authors from approving their own work. Assisted publication requires explicit confirmation.

Evidence over assumptions

Material permission, connection, approval and publishing events are designed to leave auditable evidence.

Early-access truth: these are required product controls, not a claim that every backend control or external certification is already complete. Real account connection remains disabled until token storage and tenant-isolation tests pass.