Skip to content
WickArc

WickArc / security

Security boundaries, not security slogans

How WickArc separates public product pages, authorized workspaces, and private research.

Workspace access is enforced on the server

Authentication and workspace membership checks protect research APIs. Knowing a resource identifier or hiding a browser element is not authorization. Public demo data is isolated from customer records.

Private research stays behind an explicit boundary

Customer-facing scenario responses use sanitized public fields. Private feature recipes, model weights, credentials, storage keys, and sealed holdout results do not belong in public responses. Ordinary workspace ownership does not grant private Research Core access.

Claims we do not make

These are implemented design controls, not a claim of an independent penetration test, SOC 2 certification, zero risk, or guaranteed uptime. The public demo performs no research mutation, model training, or brokerage action. Security and release reviews remain distinct from product capability.