Bounded claims
Conceptual workflow states are labelled. The site does not present a mock action as proof of a live send or provider result.
Security / evidence over theatre
What the SynthCrew public product site can verify today, what remains unconfigured, and how the product boundary treats agent actions.
This is a security posture summary for the public SynthCrew website. It separates controls implemented in the source from controls that require the final host, domain, providers, and operational owners.
Conceptual workflow states are labelled. The site does not present a mock action as proof of a live send or provider result.
The public website uses static HTML/CSS, a small local navigation script, and a narrow server-side request endpoint; no credential, provider token, or analytics SDK is embedded in the client.
Build, secret scan, route validation, accessibility, browser, and Lighthouse checks are reproducible before a release candidate is accepted.
These are the controls a buyer can evaluate now. They are product and deployment facts, not a certification, uptime promise, or legal advice.
Human access is bound to one workspace. Agent keys are separately scoped and can be revoked.
Mailbox connections belong to the workspace owner. Provider access is separate from human sign-in and never bypasses consent.
Workspace data can be read through bounded exports. Retention and deletion are policy-controlled; no public retention SLA is claimed.
Mutations return durable receipts and typed failure states. Releases retain rollback evidence; no availability SLA is promised.
Google OAuth/Gmail and Stripe may be used when configured for the workspace. No hidden analytics SDK or mailbox reseller is bundled.
For security, procurement, or deletion questions, contact [email protected]. No response-time SLA is claimed.
Evidence boundary: source and deployment checks are retained per release. Ask for the current release receipt instead of treating this page as a live status dashboard.
HTTPS, HSTS, CSP delivery, DNS, access control, deploy provenance, backups, uptime alerts, mailbox security, incident response, dependency updates, and provider permissions belong to the final deployment and operations runbook. The contact endpoint also requires provider delivery, rate-limit, log-retention, and alert ownership review; these are not silently claimed by source alone.
For a public-launch security question, email [email protected]. Do not include exploit payloads, secrets, or personal data in the initial message.
Continue with context
The public site is designed for careful evaluation. If you need product-specific context, contact rather than treating this page as an authenticated surface.
Create workspace