Tenant isolation
Organization identity comes from the authenticated server session. Request bodies and subdomains never decide authorization.
The review MVP keeps provider credentials server-side, scopes tenant records by organization, and avoids storing passports or traveler payment cards.
Organization identity comes from the authenticated server session. Request bodies and subdomains never decide authorization.
Platform credentials are server-side, redacted from logs, versioned for rotation, and never returned through agency APIs.
Deep links require HTTPS, an approved provider host, no embedded credentials, and a fresh policy check before return.
Report a security concern to security@voyagefoundry.com.