Project isolation
Workspace ownership is checked on the server for every read and write, and the acting account comes from your session rather than from the request. One workspace cannot reach another's projects.
SECURITY
Workspace ownership is checked on the server for every read and write, and the acting account comes from your session rather than from the request. One workspace cannot reach another's projects.
Private project code is processed only for requested generation, review and repair actions. It is not used to train models.
Production deployment is never triggered without an explicit user action. Integration credentials are held separately from project content and are never written into generated output.