Security

The product boundaries that protect the game.

This page is a high-level trust overview. It explains the current security posture and product boundaries without making unsupported certification, compliance, or uptime claims.

Plain-language trust surface. Slack gameplay and browser administration remain separate.

Field note

Slack install and OAuth

Workspace installation happens through Slack OAuth. The install flow verifies authorization state and hands the installer browser session into the customer console path after Slack returns successfully.

Field note

Hidden game-state boundaries

Hidden roles, private votes, night actions, and similar game state are needed to run the game correctly. Those details should not appear in ordinary player-facing web surfaces. Slack gameplay and browser administration remain intentionally separate.

Field note

Browser versus Slack

Slack is the gameplay surface. The webapp is for install, workspace configuration, billing, support, logs, and history. That separation reduces confusion and helps keep private game actions out of browser gameplay surfaces.

Field note

Public commitments we are not making

This page does not claim certifications, compliance programs, SOC 2, GDPR readiness, DPA support, or guaranteed uptime unless those capabilities are separately implemented and documented.

Field note

Reporting concerns

Security concerns, suspicious installs, or data-boundary questions should go through the contact route so they can be handled through the support/admin process.