Operations
Security and privacy
Identity isolation, token handling, external media, and responsible generation.
Implemented controls
- OAuth 2.1 authorization-code flow with PKCE and exact redirect validation
- Hashed access, refresh, authorization-code, and confidential-client secrets
- Per-user database scoping for jobs, assets, characters, moodboards, and credits
- HTTPS-only external media URLs in production
- Explicit destructive and read-only annotations on MCP tools
- No password sharing with an agent or connector
User responsibilities
- Use only media you have rights to process.
- Obtain consent before cloning or training a real person’s identity or voice.
- Review generated claims, labels, logos, and text before commercial publication.
- Disconnect clients and revoke credentials that are no longer needed.