Application boundary
Strict CSP, HSTS, same-origin isolation, no framing, and minimal browser permissions.
Trust and security
Ghost Core protects collaboration by keeping authority explicit, secrets server-side, telemetry privacy-safe, and evidence separated from customer content.
Strict CSP, HSTS, same-origin isolation, no framing, and minimal browser permissions.
Rate limits, bounded request bodies, validated uploads, and fail-closed sensitive endpoints.
Server-only credentials, automated secret scanning, redacted errors, and no sensitive debug logs.
Pinned lockfiles, dependency audits, build gates, and review of high-risk updates.
Privacy-safe security events, escalation ownership, containment runbooks, and post-incident verification.
Agent and support actions are bounded by explicit leases, audit events, and revocation behavior.