Security & permissions

Authority is a product boundary, not a configuration detail.

Rootspan’s current design-partner workflow is supervised and read-only by default. The evidence needed for a diagnostic is intentionally narrower than a merchant’s full operating data.

Control model

Permission stays visible at every step.

01

Read-only first

Begin with permitted observation. External action is outside the default authority boundary.

02

Least privilege

Scope evidence to the merchant, systems, and fields needed for the diagnostic.

03

Evidence references

Keep source identity, timestamps, and hashes without copying raw values into logs or analytics.

04

Proposed diffs

Describe the exact field, basis, affected entities, uncertainty, rollback, and verification plan.

05

Human approval

Keep the accountable operator between a proposal and any future external write.

06

Audit continuity

Retain safe receipts and transition records so the case can be reconstructed.

Excluded data

A scoped diagnostic does not require the keys to the kingdom.

Passwords, API secrets, or credentials

Payment, card, or banking information

Customer names, addresses, or order-level PII

Unredacted exports in the website inquiry

Advertising audiences or bidding data

Pilot lifecycle

Scope access. Retain deliberately. Revoke cleanly.

Exact pilot terms are agreed before any permitted material is provided.

Before

Document sources, permissions, exclusions, retention intent, and accountable contacts.

During

Use references and redacted events; keep evidence access scoped and time-bound.

After

Revoke access, honor the agreed deletion path, and retain only approved audit facts.

Security contact

Report a concern to the monitored security mailbox.

Send vulnerability reports and security concerns to security@rootspan.ai. Do not send credentials, customer data, or active exploit payloads in an initial message.

Email security@rootspan.ai ↗View security.txt ↗