SECURITY / ARCHITECTURE COMMITMENTS
Truth is valuable only when access and change are accountable.
Wooho is designed around server-owned writes, least privilege, explicit tenant scope, immutable evidence, and human review. These are architecture commitments, not third-party assurance claims.
Identity and access
Verified Firebase identities receive server-side tenant membership and role checks. Privileged roles require MFA. Sessions are revocation-checked, CSRF-protected, and App Check capable.
Tenant isolation
Tenant identity is required in document paths, service contracts, tasks, retrieval filters, caches, audit events, billing metadata, and notifications. Cross-tenant denial is a release gate.
Source and AI safety
Uploads are signed, immutable, validated, and quarantined. Retrieval rechecks canonical approval and freshness. Model output cannot directly publish truth.
Commerce
Entitlements are server-owned and must come from verified replay-safe Polar events. Browser redirects never grant access.
Vulnerability reporting
A public security address and response SLA are not yet approved. Until then, customers use the private account-provisioning channel; no unsupported public inbox is advertised.