SECURITY
Security and data governance
BrazilStack is built around least privilege, workspace isolation and minimal logging.
Authentication model
Public MCP access uses OAuth discovery and API keys. Dashboard access is identity-based through the authentication provider.
API-key storage philosophy
API keys are shown once at creation and stored hashed. BrazilStack never displays a full key again after creation.
Workspace isolation
Data is isolated per workspace and per product. BrazilStack tables are namespaced and every record carries a product tag.
Encryption
Third-party credentials are encrypted at rest with authenticated encryption before storage.
Third-party credentials
Where a source requires credentials, they are supplied by the user and encrypted at rest, never logged in plain text.
Logging minimization
BrazilStack avoids storing private MCP query content. Marketing analytics never receive query content.
Source restrictions
Sources with usage restrictions are flagged in the catalog and surfaced in the acceptable-use policy.
Vulnerability reporting
Report security issues privately. We acknowledge reports and coordinate disclosure responsibly.