3 knowledge units
Replayable authorization and tamper-evident evidenceBuildWithHQ’s security design aims to preserve enough historical authorization state and logged evidence to reconstruct whether past sensitive access was valid.Secure fields, secrets, and disclosureSensitive values can be structurally excluded from normal search/AI paths, with decryption or disclosure treated as a separate privileged and auditable operation.Security invariantsSecurity is designed as a shared structural layer: server-derived identity, one authorization path, explicit tenant/application/location scope, and separate permissions for read, AI, export, and sensitive disclosure.