Trust at Cards

Trust should be visible, too.

Cards holds the work, conversations, decisions, time, and client information teams rely on. You should be able to understand what Cards can see, how access is controlled, and what the system will never decide about a person.

Two Parts of Trust

Operational protection and human dignity belong together.

Operational Trust
  • Authentication and workspace isolation
  • Roles and permission boundaries
  • Private files and controlled access
  • Audit history and recovery controls
One accountable system
Human Trust
  • Transparency without surveillance
  • Accountability flowing both ways
  • No automated judgments about people
  • Human ownership of consequential decisions
Access Boundaries

Access follows identity, role, and context.

Cards verifies who someone is, where they belong, what role they hold, and whether a requested action is permitted before a protected change is made.

IdentityAuthenticated person
MembershipActive workspace
RoleAllowed surfaces
RecordVisible in context
CommandServer validated
HistoryProtected result
Client IdentityAuthenticated reviewer
Client ScopeInvited project
Shared WorkClient-visible only
DecisionReview or approval
HistoryConnected to the chain
Accountable Support

Help without hidden impersonation.

When account-level assistance requires Cards to inspect a customer experience, access is narrow, temporary, visible, and recorded.

An active case and explicit reason are required.Support access begins with a specific customer need, not open-ended browsing.
The session is read-only and lasts no more than 15 minutes.Attachments cannot be downloaded, and the operator remains the accountable actor.
No hidden customer membership is created.Cards does not create an impersonation credential or silently join the customer workspace.
Starting and ending access are recorded.The support history exists for both Cards operations and the customer account.
Current Controls

Protection built into ordinary operation.

Private Files

Attachments live in private storage. Visibility follows the workspace and the work record; client access is limited to files explicitly connected to client-visible work. Files are scanned before normal release, and unsafe files are quarantined.

Monitoring Without Recording People

Cards monitors application errors and service availability. Session replay is disabled, and performance tracing remains off pending separate privacy review. Monitoring is for understanding whether Cards works—not recording how individuals behave.

Recovery and Release Safety

Cards uses encrypted off-site backups, isolated restore testing, separate staging and production environments, controlled production promotion, and preserved rollback paths during release observation.

A Narrow Job for AI

CardBot can surface the record. You decide what it means.

AI can help prepare information and ask better questions. It does not become an unaccountable participant in decisions about people.

01
CardBot creates reviewable Plan Drafts. It cannot create a live Project without human approval.
02
Assignments, relationships, permissions, schedules, and persistence remain governed by deterministic Cards rules.
03
Planning Context is permission-filtered and intentionally excludes Card titles, descriptions, comments, attachments, and absence reasons.
04
CardBot does not judge motives, competence, character, or employee performance.
Plain Language

What Cards does not claim.

  • Cards is not currently presented as SOC 2 or ISO 27001 certified.
  • Cards does not claim zero access or end-to-end encryption.
  • Cards does not claim that incidents or outages are impossible.
  • This page does not replace the Privacy Policy, Terms, or contractual data commitments.
  • Future controls will never be presented as protections that exist today.
Keep Asking

Trust grows through shared understanding.

If something here is unclear, ask. Cards should be as accountable for the environment it creates as the people who rely on it.