Security

Security and data boundaries

Understand authentication, tenant access, support uploads, payment services, and operational audit boundaries.

Authentication and tenant access

Discord OAuth identifies the user. Server routes verify the selected guild and the user's current management permission before returning tenant data.

Support uploads

Support uploads use a private support-only object store. Files remain quarantined until type, size, checksum, and malware checks complete. Public asset URLs are not used for support attachments.

Billing boundary

Payment credentials and detailed service responses remain restricted. The browser receives only the fields needed for the supported billing workflow.