Security

Practical safeguards for controlled technical work.

Pebblyhill combines organization scoping, authenticated private-file access, role-aware commands, immutable audit history, and explicit controlled-record workflows. This page describes the current early-pilot approach, not a certification claim.

Workspace isolation

Operational records are organization-scoped. Server actions verify the authenticated user, membership, organization, role, and expected record version.

Private file access

Controlled files use authenticated, organization-scoped reads rather than public download URLs. File access follows object and membership permissions.

Controlled mutations

Important workflow decisions use server-authoritative commands, idempotent command identifiers, receipts, and immutable audit events.

Authentication and roles

Firebase Authentication establishes identity. Workspace roles and team assignments govern administration, review, approval, and operational actions.

Data retention

Retention, legal hold, and controlled-record locks prevent ordinary deletion where history must be preserved.

Managed operations

The early pilot runs as a managed cloud service. Environment secrets remain server-side and are not bundled into browser code.