Security and control

Cascand can decide what deserves attention. You decide what it is allowed to do.

That is the whole security model. Here is what it means in practice.

Your systemsCRM · Mailbox · Calendar · LinkedIn
Cascand, on its ownResearch · Decide · Prepare · Verify
YouApprove, every time it matters
Then, and only thenThe external action happens

Always available to you: Pause · Revoke · Disconnect · Export

In practice

Consequential software should be controlled. Cascand is.

  • Your data stays under your control

    Your connected systems remain yours. Cascand reads from them and writes back to them according to the access you authorize.

  • Your account is isolated

    Each customer account is isolated from every other customer. Access is enforced at the account boundary, not only in the interface.

  • You decide what Cascand can do

    Permissions are explicit and per capability. Connect only what you want. Pause Cascand for a person, a team or a capability at any time. Disconnect a system and Cascand's access ends with it.

  • Cascand can reason without you. It cannot act without you.

    It can research, prepare and organize work within the limits you set, entirely on its own. Consequential external actions, a send, a booking, a CRM update, always require your approval.

  • Cascand does not assume an action succeeded

    It confirms important actions with the system that performed them, and tells you Uncertain when it cannot. Never a false Done.

  • Credentials are protected

    Connection credentials are encrypted at rest, can be rotated, and are never shown in the product or written to logs. Cascand does not hold your LinkedIn password.

  • Untrusted text stays text

    What arrives from email, the web or a spreadsheet is treated as information, never as instructions. It cannot make Cascand act.

  • Everything is on the record

    Every recommendation, approval and action is kept in a tamper-evident audit trail: even Cascand's own systems cannot quietly edit it. You can see what Cascand decided, what it did, and why.

  • You can leave

    Export everything your account holds at any time. Ask for identifying data to be erased and it is.

For your security review

The straight answers.

Where is data held
In Cascand’s database on Supabase, with account isolation enforced in the database itself, not only in the application.
Who can access it
People you invite, with roles you assign. Access checks fail closed.
Which outside services see it
Anthropic, as Cascand’s model provider for certain language tasks, and Supabase for the database and login. Your CRM, mailbox, calendar and LinkedIn connection are your own accounts, connected directly.
Can Cascand act on its own
Cascand can reason and prepare without you: research, drafting and organizing work, within the limits you set. It cannot cause a consequential external effect without you.
What if something goes wrong
Pause everything, one team, one person or one capability, instantly. Nothing runs that should not, and a retry never becomes a duplicate.
Single sign-on and provisioning
Built and tested for enterprise accounts. Certification with your specific identity provider happens together, during setup.
Certifications
Cascand has not yet completed a third-party audit or penetration test. We say so plainly rather than imply otherwise, and we are happy to walk your security team through how the product works.