PaperPlanes GEO

Security

Isolation and evidence integrity by design.

PaperPlanes GEO uses authenticated, organization-scoped access with separate workspace roles. PostgreSQL row-level policies enforce workspace boundaries in addition to application authorization.

Raw provider responses and original uploads are immutable evidence. Private files use short-lived authorized downloads. Secrets, raw answers, truth statements, and customer documents are excluded from product analytics and application logs.

Support access must be explicit, time-limited, and audited. The service includes workspace export, retention deletion, provider kill switches, bounded retries, and deployment rollback procedures.