Security

Controls that are in place today — described in plain language.

Governed tool use

Digital coworkers propose structured plans. Plans are validated and checked by policy before any tool runs. Allowlists, authorization, and iteration limits apply.

Honest failures

When a tool fails or is unavailable, Selra shows clear status. Respond paths are instructed not to invent sources or results.

Verified access

Authorized users sign in with a secure email link. Sessions expire. There is no open public signup.

Scoped integrations

Connectors are intended to be least-privilege (for example read-oriented search when configured). Product credentials are not embedded in this marketing site.

This website

  • Static marketing pages.
  • No application secrets in client assets.
  • Security headers via _headers (nosniff, frame denial, referrer policy).

Hosting

The public site is served from Cloudflare Pages. Private workspaces use identity-gated access appropriate to the deployment. Details are covered during early-access setup.

Report an issue

Email [email protected] with “Security” in the subject. Include enough detail to reproduce; do not include unrelated customer data.