Access starts closed.
Authorization defaults to deny wherever a request, document, upload, or job crosses a tenant boundary. Organization membership and project roles define the work a person can access.
Ligata trust center
Security is designed into access, content handling, and the services that prepare an edition. This page explains the commitments built into Ligata’s accepted architecture.
Authorization defaults to deny wherever a request, document, upload, or job crosses a tenant boundary. Organization membership and project roles define the work a person can access.
Secrets do not enter the browser, live page documents, job payloads, or logs. Provider credentials are envelope-encrypted and are held in worker memory only while an operation is active.
Uploads are checked for size and file type and can be malware scanned. Themes cannot run code. Import and publishing work within CPU, memory, time, and network constraints.
Interface controls are helpful, but they are not the security boundary. Authorization is repeated across the API, synchronization, collaboration, storage, and worker services.
Sensitive logs and recordings of AI input and output are disabled by default. This keeps the operational record appropriately narrow.
Comments, suggestions, and AI results are review objects, not silent edits. Restoring earlier work creates a fresh page generation rather than merging an old snapshot into the current manuscript.
Questions about Ligata
Read the FAQ