Skip to main content
Pirouetta BackstageSign in

Trust and security

Security starts with clear boundaries

Understand the identity, tenancy, permission, provider, and reporting boundaries represented in Corsaca today.

Trust resource

Published overviewLast updated July 16, 2026Questions about this page
01

Authenticated access

Corsaca uses authenticated sessions for protected application areas. A signed-in account does not automatically receive access to every application, organization, or record.

02

Role and permission checks

Application behavior is designed to evaluate tenant membership, role assignments, and permissions before presenting or executing protected operations.

03

Application and tenant scope

Records and workflows are designed around application and tenant context. Row-level access controls and server-side checks protect supported data paths.

04

Server-side credentials

Service credentials, payment secrets, and Google service identity material belong in managed server-side configuration and must not be exposed to browser or mobile clients.

05

Report a security concern

Send a concise description, affected product, approximate time, and safe reproduction details to support. Do not include passwords, authentication codes, secret keys, or complete payment credentials.

Questions about this resource?

Talk with the team responsible for the next step.

Share the product, organization, and policy topic involved. Corsaca will route the question without asking you to place credentials or complete payment details in email.
Email supportVisit Help Center