This page lists what is true of the system and how each thing is held. It does not list certifications, because we do not hold any yet, and it does not quote an uptime figure, because we have not published one.
Not a client column with a filter in every query. A separate database, so a bug in one query cannot show one client another client’s leads, replies or mailboxes.
Shared state is limited to what must be shared: user accounts, the plan catalogue and billing records.
Scheduled jobs are read-only syncs. One may pause a losing variant. The only automated send is the delivery of a reply a person approved, at the time they chose.
Follow-on lanes derived from a campaign a person launched (an out-of-office resume, a referral copy) run inside that launch and only while five guards hold, one of which is that the workspace has not opted out.
Roles are owner, member and viewer within a workspace, and an operator role that is never granted by sign-up. A workspace owner manages their own team, integrations and credentials; secrets are write-only once stored.
An unverified workspace can be explored but cannot verify leads or spend credits. The resend endpoint answers the same way whether or not the address exists, so it cannot be used to enumerate accounts.
Approvals, edits, launches, pauses, purchases, invitations. When a verification email could not be sent, the log says so rather than pretending it went.
It is a security property as much as an honesty one: a fabricated healthy figure is how an estate burns quietly while the screen stays green.
When a change involves an upstream provider, the provider is updated first and the local record second, so an upstream failure surfaces as an error and the workspace never believes something that did not happen.
When any of these changes, this page will change with it. Until then, absence here means absence.
Every workspace is created with one.