Security
What CadreGPT enforces today, and how we think about agent safety.
In place today
- Authentication — email + password sign-in with server-side sessions stored in PostgreSQL.
- Organization isolation — API routes derive tenant context from the authenticated session; membership is checked server-side.
- Audit trail — action audit ledgers record what agents did.
- Approval queues — high-risk capability calls are designed to pause for human authorization.
- Secret hygiene — provider credentials are stored as references, resolved at runtime, and redacted in logs.
Honest roadmap
We will not overstate maturity: independent third-party outcome verification, full capability-policy enforcement at runtime, and formal security certifications are on the roadmap, not claimed as complete. Billing (Polar) is architecture-only and not activated.