Browse documentation
Operations

Security and privacy

Identity isolation, token handling, external media, and responsible generation.

Implemented controls

  • OAuth 2.1 authorization-code flow with PKCE and exact redirect validation
  • Hashed access, refresh, authorization-code, and confidential-client secrets
  • Per-user database scoping for jobs, assets, characters, moodboards, and credits
  • HTTPS-only external media URLs in production
  • Explicit destructive and read-only annotations on MCP tools
  • No password sharing with an agent or connector

User responsibilities

  • Use only media you have rights to process.
  • Obtain consent before cloning or training a real person’s identity or voice.
  • Review generated claims, labels, logos, and text before commercial publication.
  • Disconnect clients and revoke credentials that are no longer needed.