Security & privacy
Identity
Section titled “Identity”Sign-in uses short-lived access tokens; authority (roles, tenant scope) is resolved server-side per request — not embedded in tokens.
Hosting
Section titled “Hosting”Production workloads run in the EU. Operational details and subprocessors are published on the marketing site as legal pages mature.
Report an issue
Section titled “Report an issue”Use security@capitality.io when that mailbox is listed in our security.txt.