A security page that reads as complete is the one nobody trusts.
| Control | Status | Evidence |
|---|---|---|
| Every query names the tenant; no ambient organisation | in place | One resolver for app, agent and MCP |
| No agent tool accepts an organisation as an argument | in place | Pinned by a test that reads the source |
| Operator access mints an ordinary membership you can see and remove | in place | Visible in your members list |
| Connector credentials sealed at rest, never rendered back | in place | AES-256-GCM; weak keys refused in production |
| Outbound requests refuse private and internal addresses | in place | On the literal, every resolved address, every redirect |
| Customer text flattened before it reaches a brief or an issue | in place | Legible, never executable |
| No agent decides, dispatches or writes a measure | in place | Registry test; no tool carries the decide scope |
| Work leaves only with a named person on it | in place | The dispatch writer requires an authoriser |
| Nothing sent to a customer on anyone's behalf | in place | Drafts only; a person sends |
| Security log append-only at the database | in place | Delete refused by trigger; readable by you |
| Decisions kept with reasoning; every field change recorded | in place | Decision and revision registers |
| Content security policy with per-request nonce | in place | No inline script without it |
| Approved email domains, invitations, roles | in place | Standing invitation per domain |
| SSO (SAML / OIDC) for enterprise tenants | planned | Google sign-in today |
| SOC 2 Type II for Goal itself | planned | TeamForm's programme is SOC 2 Type II; Goal is newer |
| Run inside your own cloud | planned | Same product; offered to enterprise tenants on request |
| Export of every register | planned | Your goals, decisions and readings, on request today |
Enter your email address to view.
invited addresses get instant access