SECURITY

Security and data governance

BrazilStack is built around least privilege, workspace isolation and minimal logging.

Authentication model

Public MCP access uses OAuth discovery and API keys. Dashboard access is identity-based through the authentication provider.

API-key storage philosophy

API keys are shown once at creation and stored hashed. BrazilStack never displays a full key again after creation.

Workspace isolation

Data is isolated per workspace and per product. BrazilStack tables are namespaced and every record carries a product tag.

Encryption

Third-party credentials are encrypted at rest with authenticated encryption before storage.

Third-party credentials

Where a source requires credentials, they are supplied by the user and encrypted at rest, never logged in plain text.

Logging minimization

BrazilStack avoids storing private MCP query content. Marketing analytics never receive query content.

Source restrictions

Sources with usage restrictions are flagged in the catalog and surfaced in the acceptable-use policy.

Vulnerability reporting

Report security issues privately. We acknowledge reports and coordinate disclosure responsibly.