Security
Isolation and evidence integrity by design.
PaperPlanes GEO uses authenticated, organization-scoped access with separate workspace roles. PostgreSQL row-level policies enforce workspace boundaries in addition to application authorization.
Raw provider responses and original uploads are immutable evidence. Private files use short-lived authorized downloads. Secrets, raw answers, truth statements, and customer documents are excluded from product analytics and application logs.
Support access must be explicit, time-limited, and audited. The service includes workspace export, retention deletion, provider kill switches, bounded retries, and deployment rollback procedures.