Tenant boundaries
Konteks authorization and catalog access are tenant-scoped. Credentials and permissions should grant only the access needed for the intended workspace and action.
Security
Konteks is built around scoped context, revocable credentials, explicit approval, tenant boundaries, and evidence. We publish controls we can stand behind—not certification theatre.
Konteks authorization and catalog access are tenant-scoped. Credentials and permissions should grant only the access needed for the intended workspace and action.
Provider and connector credentials are kept in protected secret storage. Public APIs, MCP discovery, prompts, screenshots, and routine logs must not reveal raw secret material.
Costed work is designed around an explicit proposal and approval boundary. High-impact mutations remain subject to permissions, policy, budget, and human confirmation.
Sessions, proposal versions, approvals, runs, validation, usage, and outcomes are correlated so teams can understand what happened and why.
MCP and connector credentials can be scoped, rotated, revoked, and replaced. Access should be removed promptly when a person, agent, or integration no longer needs it.
If you believe you found a vulnerability, do not test against other tenants or access data that is not yours. Send the details privately to hello@konteks.io.