Protected workspace access
Email and password authentication, signed HTTP-only sessions, protected application routes, and role-aware administrative actions.
Security
Praecis is designed around scoped authorization, explicit account mapping, protected administration, encrypted credentials, and evidence-aware reporting.
Email and password authentication, signed HTTP-only sessions, protected application routes, and role-aware administrative actions.
OAuth is used wherever supported. Provider passwords are not collected or stored by Praecis.
WebMCP tools are authenticated, page-bound, tenant-scoped, and draft-first. A human reviews the company and proposed source mappings before activation.
Access and refresh credentials are encrypted before database storage and used only for the authorized synchronization purpose.
Connections, accounts, metrics, competitors, actions, and billing state are isolated by workspace and company identifiers.
Scheduled workers record last success, provider state, retries, and actionable failures instead of silently serving stale data.
Source failures and unhealthy synchronization states are surfaced to operators with the affected company and provider context.
Application health, connector operations, and production failures are monitored so service issues can be detected and investigated.
Database backups and documented recovery procedures support restoration when operational incidents affect stored workspace data.
Administrative and workspace mutations are authenticated and recorded with the actor and affected object where supported.
Responsible use
Praecis is built for least-privilege, read-oriented reporting connections. You decide which provider identity to authorize and which discovered account belongs to each company.
If you believe you have found a security issue, do not include credentials or sensitive customer information in ordinary email. Contact support@praecis.co with “Security report” in the subject so we can coordinate a safe disclosure path.