PALCYAI • SECURITY & PRIVACY
Security & Privacy Controls
PALCIDUSAI uses layered controls. Client-side deterrence is not treated as a substitute for backend security.
Transport
HTTPS/TLS for public service traffic.
HTTPS/TLS for public service traffic.
Access control
Owner consoles use authenticated sessions and privileged backend functions.
Owner consoles use authenticated sessions and privileged backend functions.
Data minimization
Public intake asks for only the fields needed for the requested workflow before consented submission.
Public intake asks for only the fields needed for the requested workflow before consented submission.
Database protection
Relevant tables use row-level security and public roles do not receive service-role privileges.
Relevant tables use row-level security and public roles do not receive service-role privileges.
Secret protection
Provider secrets belong in server-side secret storage, never frontend code, prompts, public Git or customer notes.
Provider secrets belong in server-side secret storage, never frontend code, prompts, public Git or customer notes.
Webhook protection
Provider webhook routes verify signatures before processing inbound events.
Provider webhook routes verify signatures before processing inbound events.
Integrity
Idempotency, rate limiting and immutable/auditable event records protect workflow integrity.
Idempotency, rate limiting and immutable/auditable event records protect workflow integrity.
Copy/inspection deterrence
The public UI may disable normal copy, context-menu and selection actions to reduce casual copying. This is a deterrent, not cryptographic protection.
The public UI may disable normal copy, context-menu and selection actions to reduce casual copying. This is a deterrent, not cryptographic protection.
Emergency stop
Outbound automation can be paused while audit logging remains available.
Outbound automation can be paused while audit logging remains available.
Security contact
Privacy · Terms · Data Rights · Back