Permissions
AI Employees operate within configured roles, capabilities, integrations and permissions. Protected operations are subject to authorization checks.
Security
Polyosync is designed around permissions, tenant boundaries, protected credentials, auditability and controlled AI actions. Security controls are part of the platform architecture.
Security controls
AI Employees operate within configured roles, capabilities, integrations and permissions. Protected operations are subject to authorization checks.
Sensitive OAuth and API credentials are encrypted or otherwise protected server-side. HTTPS/TLS protects data in transit. We do not make blanket encryption-at-rest claims beyond verified provider and application controls.
Business-level isolation is enforced through tenant-scoped authorization and database access controls. A business workspace is the application data boundary for protected resources.
Security and audit telemetry records relevant authentication, authorization and operational events so activity can be investigated.
Resource-level access checks and workspace membership controls restrict who can access protected business resources and actions.
Configured approval policies can require human approval before defined AI actions are executed.
Operational security
Polyosync tracks relevant authentication, API, workflow and security signals for investigation, incident response and service reliability. Privileged Platform Admin access has additional controls, including authenticator-app TOTP MFA on the relevant routes.
This page describes implemented controls and documented practices. Polyosync does not claim SOC 2, ISO 27001, penetration-test certification or another independent certification unless that certification is actually held and documented.
Related controls
Copy system
Every Polyosync page answers the same operational questions. No vague AI claims: what it is, what it does, how it operates, what it automates, and where people stay in control.
The controls around AI execution: permissions, access boundaries, credential protection, tenant isolation, audit and human intervention.
Role + business knowledge + capabilities + authorised tools + integrations + defined workflows. The configuration determines what the AI can access and do.
Teams evaluating how AI execution is constrained and governed in a business environment.
Controls can stop, approve or route work to people instead of allowing AI to continue outside its defined authority.
Apply the same control model from individual employees to broader AI workforce deployments and enterprise environments.
Availability
Security capabilities described here reflect the current product architecture; they should not be read as unsupported certification claims.