Research workspaceAccount

Data and security boundaries

Protect local papers, account tokens, source URLs, and model credentials across native and server components.

Data and security boundaries — contract and behavior

  • Local PDFs remain local unless an explicit enrichment or sync workflow uploads content.
  • The native client stores only publishable configuration and user session material appropriate to a desktop app.
  • Service-role, model-router HMAC, and provider credentials never ship in the app bundle.
  • Logs and crash reports must not include paper contents, private source URLs, or session tokens.

Stay in the loop. Never miss out.

Subscribe to our newsletter and unlock Wisent insights.