- workspaces and projects are tenant-scoped;
- P2HS is authoritative for ownership, entitlements, capability admission, and usage policy;
- managed runtime services execute only admitted work;
- secrets are policy-controlled assets with explicit propagation targets;
- provider credentials are not exposed to browser clients;
- webhook signatures and provider events are verified before reconciliation;
- MCP clients use scoped grants and tool authorization;
- generated applications should use approved server-side or trusted-client flows.
Platform
Security overview
Understand P2HS security boundaries for tenants, secrets, integrations, and AI clients.
P2HS treats security as a set of explicit boundaries:

