Security
Updated 22 August 2026
SynPulse uses tenant isolation, least-privilege access, encrypted account credentials, authenticated webhooks, rate limits, audit trails, and separate controls for draft creation and external launch.
Authentication and MCP
Production authentication uses verified email, PKCE, scoped access tokens, refresh-token rotation, and a resource-bound MCP audience. AI clients invoke external actions through the host confirmation flow; the MCP App iframe has no direct credential or API access.
Operations
Secrets are supplied at runtime, sensitive values are excluded from client output and logs, dependencies and containers are scanned, and backups are encrypted and periodically restored in a controlled test.
Responsible disclosure
Test only accounts and data you own. Avoid privacy violations, disruption, social engineering, denial of service, and destructive actions. We will acknowledge a valid report, investigate it, and coordinate remediation and disclosure in good faith.