Authenticated access
Corsaca uses authenticated sessions for protected application areas. A signed-in account does not automatically receive access to every application, organization, or record.
Role and permission checks
Application behavior is designed to evaluate tenant membership, role assignments, and permissions before presenting or executing protected operations.
Application and tenant scope
Records and workflows are designed around application and tenant context. Row-level access controls and server-side checks protect supported data paths.
Server-side credentials
Service credentials, payment secrets, and Google service identity material belong in managed server-side configuration and must not be exposed to browser or mobile clients.
Report a security concern
Send a concise description, affected product, approximate time, and safe reproduction details to support. Do not include passwords, authentication codes, secret keys, or complete payment credentials.