Identity before execution
Protected backend actions identify the principal, validate installation or license state, check backend entitlement, verify quota, and only then allow execution.
Ease uses scoped identity, cloud-managed infrastructure, explicit entitlement checks, and operational traceability to protect reporting workflows.
Protected backend actions identify the principal, validate installation or license state, check backend entitlement, verify quota, and only then allow execution.
Team access requires a named, verified membership and an available seat. Ease does not grant workspace access because a user shares an email domain with the purchaser.
Connections use provider authorization mechanisms and requested scopes. Users can disconnect sources and revoke provider access independently.
API and worker responsibilities are separated. Asynchronous jobs are dispatched through a controlled queue, while internal workers are not exposed as public user endpoints.
Public service traffic uses HTTPS. Google Cloud services provide encryption in transit and at rest; sensitive configuration belongs in managed secret storage.
Run identifiers, state transitions, entitlement decisions, and operational events support investigation and troubleshooting without relying on spreadsheet output alone.
Firestore is used for metadata, status, pointers, and small records. Cloud Storage is reserved for larger artifacts and optional archived report versions.
Forecast Builder produces deterministic calculations. AI Analysis and Explain this forecast are separate actions that produce interpretive output.
If you believe you found a vulnerability or unauthorized access, do not include live credentials, access tokens, or sensitive customer data in your first message.