- Authentication and workspace isolation
- Roles and permission boundaries
- Private files and controlled access
- Audit history and recovery controls
Trust should be visible, too.
Cards holds the work, conversations, decisions, time, and client information teams rely on. You should be able to understand what Cards can see, how access is controlled, and what the system will never decide about a person.
Operational protection and human dignity belong together.
- Transparency without surveillance
- Accountability flowing both ways
- No automated judgments about people
- Human ownership of consequential decisions
Access follows identity, role, and context.
Cards verifies who someone is, where they belong, what role they hold, and whether a requested action is permitted before a protected change is made.
Help without hidden impersonation.
When account-level assistance requires Cards to inspect a customer experience, access is narrow, temporary, visible, and recorded.
Protection built into ordinary operation.
Private Files
Attachments live in private storage. Visibility follows the workspace and the work record; client access is limited to files explicitly connected to client-visible work. Files are scanned before normal release, and unsafe files are quarantined.
Monitoring Without Recording People
Cards monitors application errors and service availability. Session replay is disabled, and performance tracing remains off pending separate privacy review. Monitoring is for understanding whether Cards works—not recording how individuals behave.
Recovery and Release Safety
Cards uses encrypted off-site backups, isolated restore testing, separate staging and production environments, controlled production promotion, and preserved rollback paths during release observation.
CardBot can surface the record. You decide what it means.
AI can help prepare information and ask better questions. It does not become an unaccountable participant in decisions about people.
What Cards does not claim.
- Cards is not currently presented as SOC 2 or ISO 27001 certified.
- Cards does not claim zero access or end-to-end encryption.
- Cards does not claim that incidents or outages are impossible.
- This page does not replace the Privacy Policy, Terms, or contractual data commitments.
- Future controls will never be presented as protections that exist today.
Trust grows through shared understanding.
If something here is unclear, ask. Cards should be as accountable for the environment it creates as the people who rely on it.
