GrekSignal

GrekSignal early access

How GrekSignal handles access and evidence

Security claims should describe controls that exist. GrekSignal uses authenticated server boundaries and scoped records, while remaining review and recovery work is stated explicitly.

01

Organization and project access

Server APIs verify the signed-in identity and current organization membership. Mutations recheck project ownership and editor roles. Browser access to project collections is denied; owner identity cannot be changed through client rules, and later team role changes use the owner-only server workflow.

02

Credentials and external actions

Google and customer webhook secrets are encrypted on the server. API keys are hashed, scoped, expiring and revocable. Session origin checks, browser-bound OAuth state and raw-body webhook signatures protect supported entry points. Public fetches use safe address checks and bounded requests.

03

Known operational limits

No certification, independent penetration test or recovery-time promise is claimed. The existing Firestore database has point-in-time recovery and delete protection disabled; backup restoration was not verified. Moderate production dependency advisories and development-tool advisories remain under review before unconditional general availability.

Practical questions

Are credentials included in client reports or Copilot context?

Supported sanitized reports and compact AI context exclude provider credentials and session secrets.

Are backups guaranteed?

No. Backup and restore configuration needs operator verification; this page makes no backup guarantee.

Start with observable evidence

Run the bounded public scan on the homepage, then save a project when you are ready. Connected measurements need real authorization and available quota.