Ligata trust center

Clear boundaries for the work around your book.

Security is designed into access, content handling, and the services that prepare an edition. This page explains the commitments built into Ligata’s accepted architecture.

Access

Access starts closed.

Authorization defaults to deny wherever a request, document, upload, or job crosses a tenant boundary. Organization membership and project roles define the work a person can access.

Secrets

Secrets stay out of the manuscript.

Secrets do not enter the browser, live page documents, job payloads, or logs. Provider credentials are envelope-encrypted and are held in worker memory only while an operation is active.

Automation

Automation has limits.

Uploads are checked for size and file type and can be malware scanned. Themes cannot run code. Import and publishing work within CPU, memory, time, and network constraints.

The safeguards are part of the workflow.

Roles are checked at every seam.

Interface controls are helpful, but they are not the security boundary. Authorization is repeated across the API, synchronization, collaboration, storage, and worker services.

Sensitive recording is off by default.

Sensitive logs and recordings of AI input and output are disabled by default. This keeps the operational record appropriately narrow.

Accepted content remains a human decision.

Comments, suggestions, and AI results are review objects, not silent edits. Restoring earlier work creates a fresh page generation rather than merging an old snapshot into the current manuscript.

Questions about Ligata

Read the FAQ