PERSIDIAN

Trust

Security

Integration scopes

Each Persidian agent requests the minimum OAuth or API scopes needed for its job. Product entity pages list what each agent can read and write. Write paths are gated at the tool layer — not only in prompts.

Encryption and transport

All public surfaces are served over HTTPS. Third-party integrations use provider-standard OAuth and TLS. Credentials are stored in environment-isolated configuration, never in client-side code.

SSRF and scan safeguards

The Business X-ray blocks private, localhost, link-local, and cloud metadata addresses. Redirects are revalidated. Page, time, and redirect budgets cap each scan.

Incident contact

Report a security concern to [email protected]. Include reproduction steps and affected product if known.

Related

Trust and data handling · Privacy