1. Authentication
- Web sign-in is delegated to a managed identity provider, so we never handle your password.
- API and MCP clients authenticate with a bearer token. Tokens are generated with a cryptographically secure random source, shown once, and stored only as a hash.
- Every token carries explicit scopes, may be pinned to a single project, and may be given an expiry date.
- Tokens can be revoked instantly, and last-used timestamps make an unused token easy to spot.
2. Authorisation
Every query is scoped to the projects you own or are an active member of. There is one shared access layer used by the web views, the REST API and the MCP tools, so a permission fix applies everywhere at once.
MCP tools declare the scopes they require and are refused if the calling token lacks them. A project-scoped token filters every read and every write to that single project.
3. Safe writes for agents
Mutations requested by an external tool are never applied straight away. The tool creates a preview describing exactly what would change; the preview expires if it is not committed; committing applies the change in a single transaction and records it in the project change log with the source marked as an external tool.
Every change is attributable. The project history page shows what changed, when, and whether a person, an agent or the system did it.
4. Model provider keys
- Keys you supply are encrypted at rest with authenticated encryption.
- They are never rendered back to the browser in full.
- Creation, rotation, use and deletion are written to an audit log you can read.
- Rotating a key replaces it without losing its history.
5. Data handling
- All traffic is served over TLS.
- Backups run on a rolling window and are restricted to operational use.
- Projects and note branches can be exported as JSON, so you are never locked in.
- Deleting a project removes its notes, tasks, ideas and comments.
6. Reporting a vulnerability
Send findings to security@nibvine.com. Include a description, the impact, and the minimum steps to reproduce. We aim to acknowledge within 3 working days and to keep you updated until the issue is closed.
Please give us a reasonable window before publishing, test only against your own account, avoid denial-of-service testing, and never access or modify data that is not yours. Research that follows those rules is welcome and we will not pursue you for it.
There is no paid bounty programme at the moment. We do credit reporters who want to be named.
Questions about this document? Write to legal@nibvine.com.