Trust
Security
Integration scopes
Each Persidian agent requests the minimum OAuth or API scopes needed for its job. Product entity pages list what each agent can read and write. Write paths are gated at the tool layer — not only in prompts.
Encryption and transport
All public surfaces are served over HTTPS. Third-party integrations use provider-standard OAuth and TLS. Credentials are stored in environment-isolated configuration, never in client-side code.
SSRF and scan safeguards
The Business X-ray blocks private, localhost, link-local, and cloud metadata addresses. Redirects are revalidated. Page, time, and redirect budgets cap each scan.
Incident contact
Report a security concern to [email protected]. Include reproduction steps and affected product if known.