In scope
- larasx.com domains and subdomains
- Public hooks under /api/
- Webhook receivers and OAuth callback flows
- Partner workspace isolation, authentication, authorization bugs
SECURITY / FOR PARTNERS
How the work behind your brand keeps each partner sealed off, the chain of custody clean, and the brand boundary enforced everywhere data crosses. Your clients see your name, never ours.
Security contactFor vulnerability reports and procurement questions from your business owners, email help@larasx.com.
PARTNER WORKSPACE MODEL
Every partner account is an isolated workspace. The business owners you serve, their conversations, connected accounts, and decision logs live inside your boundary. No partner can read, enumerate, or address another partner's data through any code path that ships.
01
Each partner gets its own workspace id at signup. Every workspace-scoped query runs inside a binding that filters reads and writes to the calling partner. Cross-partner access requires a restricted operator context used only for support, audited per call.
02
Inside your workspace, each business owner you serve sits in its own sub-scope. Catalog, customers, conversations, orders, payments, and brand voice are addressed by business owner. One staff session holds the view for one business owner at a time, never blended.
03
Postgres row-level security policies are layered on every workspace table. The application binds the partner identity on every query and the database enforces it on top. A runtime role switch that makes the database the primary gate is on the enterprise hardening roadmap, additive to the application-layer isolation already in production.
CONTROLS THAT RUN TODAY
Stated as implemented. Where a control has a hardening dependency on the roadmap, the limit is named here rather than hidden as a marketing line.
BRAND BOUNDARIES
Your brand on top is contractual, not a setting. The triangulation is explicit. The work runs under your brand. It serves your business owners. It talks to their end customers. The boundary between those three roles is enforced everywhere data crosses.
COMPLIANCE POSTURE
No SOC 2 stamp, no ISO certificate as of this writing. Enterprise business owners that need a stamp can scope it through the partner agreement. The mechanics above are real today.
RESPONSIBLE DISCLOSURE
In scope
Out of scope
Reporting channel
Email help@larasx.com with technical detail and reproduction steps. PGP available on request.
Response SLA
Acknowledge within 48 hours. Critical issues fixed within 7 days. High within 30 days. Medium and below scheduled into the next release.
Safe harbor
Good-faith research under this policy will not lead to legal action. Coordinate before any testing that could impact platform availability or business-owner data.
Last updated June 16, 2026
NEXT STEP
Your brand on top. Laras underneath.
Partner application takes a few minutes. The agreement, the workspace boundary, what your clients see, and the compliance posture get reviewed together. No sales call needed to read the mechanics.