TRUST
Security
Alimango One is designed as a multi-tenant operating platform. Security controls are built around explicit tenant context, least privilege, protected integration credentials, fail-closed host boundaries, and auditable operational behavior.
Core practices
- Tenant-owned reads and writes are scoped to the resolved organization.
- Platform authority is separated from tenant authority.
- Integration secrets are kept out of public frontend bundles and tenant-facing responses.
- Production traffic uses HTTPS and security-sensitive actions are permission-gated.
- Backups, logs, validation and rollback procedures are used as part of governed production operations.
Responsible disclosure
If you believe you found a security issue, email one@alimango.app. Include enough detail to reproduce the issue without sending unnecessary personal data, credentials, tokens, or destructive proof.
Please do not access another customer’s data, disrupt production, perform denial-of-service testing, or publicly disclose an unresolved issue.