01
Data and retention
Customer data is something we carry through the life of the product: what arrives from integrations, what we derive from it, and how long it still makes sense to keep. Retention and the exact shape of subsystems will change as we ship more. When we write it down for customers, it will match what we actually run.
02
Integrations and credentials
Integrations should use scoped credentials wherever the platform allows it, and we want to avoid broad access when a narrower scope does the job. That applies both to Ember talking to third-party tools and to how we separate paths internally as the team grows.
03
Separation between customers
Stronger separation between tenants is how we expect the platform to mature. We are not spelling out a tenancy design here because it is still in motion. Architecture and trust notes will describe what we ship, not what we hoped for early on.
04
Logging and operational visibility
Logging and traceability matter both for running the service well and for helping customers see what happened during an incident. We plan to deepen operational visibility as Ember scales, as part of running something real rather than as a tagline.
05
How this page will change
Security gets deeper as the product does: clearer internal habits, better documentation for buyers, and formal assurance work when the time is right. We will not chase certificates we cannot stand behind, and we will not quietly move a line from the right column to the left one.