Smoozen security

Security boundaries are part of the product.

Smoozen uses deterministic tenant and role controls, bounded data contracts, redacted observability, signed callbacks, and explicit rollback paths.

Tenant isolation

Authenticated deterministic code establishes tenant scope and permissions. Model output cannot change authorisation.

Canonical ownership

The client remains authoritative for identity, consent, bookings, payments, safety, and final user-facing records.

Fail-safe operation

Stale data, connector failures, invalid callbacks, telemetry failures, and unavailable providers fail closed or route to manual fallback.

Security review, penetration testing, and production launch evidence remain required before public operational enablement.

Integration quickstart · Current status · Back home