Workspace boundaries
Private workspace operations require an authenticated member of that workspace. The application and the database both enforce workspace isolation, so knowing a workspace identifier does not give anyone access.
Credentials stay on the server
Provider credentials live in server configuration. The browser gets only what a page needs for the task, never provider keys or full environment settings.
People stay in control
Recommendations come with their public source. Reply drafts need a person to review them, and nothing is sent automatically to the person described.
Where this stands
These are implementation principles. They are not a certification, and there has been no independent security audit. Production controls and operating procedures need review before launch.
Reporting a problem
Please send security details privately to security@liquiduser.com.