Device-bound sessions
Devices and refresh sessions are individually visible and revocable.
This Trust Center separates active controls, internally verified states and planned capabilities. It does not replace an independent audit—it makes the current state easier to review.
Devices and refresh sessions are individually visible and revocable.
Message and file content crosses the service boundary in protected form.
Type checks, automated tests and production builds form the internal release evidence.
Attachments use private storage and short-lived access paths instead of public buckets.
The product site and Connect pilot do not depend on advertising or profile analytics.
Administrators and users can remove access without waiting for credentials to expire.
Independent protocol and implementation review is required before broad security equivalence claims.
Organisation tenancy, SSO, SCIM and policy controls require dedicated models and acceptance.
Do not send secret keys, production credentials or personal content. Describe impact, reproduction steps and the affected version.