Security and privacy
Understand access and data boundaries
How Statecraft scopes team data, sensitive workflows, retention, and external actions.
Permission: Any member can read; administrators own controls
Version 1.0 · Last verified 2026-07-15
Team authorization
Every protected action resolves the signed-in user, profile, and actual team membership on the server. Client-supplied team IDs are not trusted.
Database enforcement
Row-level security limits authenticated reads to verified team membership. Sensitive workflow writes use validated, rate-limited server routes and audit events.
Data handling
Use the least sensitive data necessary. Never place passwords, API keys, full payment details, or unrelated personal data in notes or support requests.
What Statecraft is not
Statecraft is an operating system for government-affairs work. It does not provide legal advice, guarantee policy outcomes, or replace professional review.