← Alimango Studio

TRUST

Security

Alimango One is designed as a multi-tenant operating platform. Security controls are built around explicit tenant context, least privilege, protected integration credentials, fail-closed host boundaries, and auditable operational behavior.

Core practices

  • Tenant-owned reads and writes are scoped to the resolved organization.
  • Platform authority is separated from tenant authority.
  • Integration secrets are kept out of public frontend bundles and tenant-facing responses.
  • Production traffic uses HTTPS and security-sensitive actions are permission-gated.
  • Backups, logs, validation and rollback procedures are used as part of governed production operations.

Responsible disclosure

If you believe you found a security issue, email one@alimango.app. Include enough detail to reproduce the issue without sending unnecessary personal data, credentials, tokens, or destructive proof.

Please do not access another customer’s data, disrupt production, perform denial-of-service testing, or publicly disclose an unresolved issue.

Questions: one@alimango.app

Privacy · Terms · Data deletion · Security