Tenant isolation
Every organization-scoped route resolves the caller against the organization in the path. Wrong-tenant resources return not found.
Security at Localense
Localense handles business, website, and authorized Google data. Our security model protects the tenant boundary first, then limits every user, integration, job, and agent to the access it needs.
Core controls
Every organization-scoped route resolves the caller against the organization in the path. Wrong-tenant resources return not found.
Roles, API keys, and agent clients receive explicit capabilities. Project-bound agents cannot reach another project.
Passwords are hashed. Google refresh tokens are encrypted before storage. Session and OAuth state secrets are server-side.
Production traffic uses HTTPS. Authentication cookies are HTTP-only, secure, and configured for the Localense domain.
The crawler applies redirect, body-size, timeout, concurrency, and private-network protections before processing a site.
Security-sensitive changes, background jobs, webhook deliveries, and agent access retain records for review.
Encrypted backups follow a rolling schedule. Recovery procedures and representative restore checks are part of operations.
Google integrations request read-only or narrowly scoped access. Users choose properties and can disconnect credentials.
Responsible disclosure
Please send a clear description, affected URL, steps to reproduce, and impact. Do not access data that is not yours or disrupt the service.
Security contact
sohail@localense.comWe will acknowledge a good-faith report, investigate it, and coordinate remediation. This is not currently a paid bug-bounty program.
Start with your own data
Connect read-only Google data, run the first audit, and build an evidence-backed action plan. No charge for the first 14 days.