Security by design

Security is not the headline. It’s the foundation.

Magpy is being designed to let founders move quickly without creating the isolation, access and automation problems that are painful to repair once customers arrive.

Private-beta architecture · Claims will be updated as controls become operational and independently verified.
Four foundations

Built for the moment the product becomes real.

These are architectural intentions for the private beta—not a claim of certification. Exact control status will be published and evidenced before general availability.

01

Customer separation

Design tenant context into the data layer so one missed application filter cannot expose another customer’s information.

02

Traceable activity

Record meaningful reads, changes and external actions in a way operators can inspect and customers can understand.

03

Controlled integrations

Validate external requests and put explicit approval in front of money movement or other consequential operations.

04

Model choice and privacy

Give teams control over external AI providers, data minimization and local-model options where the workload requires them.

Transparent progress

Earn trust in stages.

A credible security program distinguishes product design, operational controls and independent assurance. Magpy will not present one as another.

Private beta

Define the tenant model, permission boundaries, audit event schema, secrets handling, backup approach and incident process. Test the highest-risk boundaries before customer data enters the system.

Early customers

Operate and measure the controls, document shared responsibility, publish verified subprocessors and provide concrete security evidence to design partners.

General availability

Publish accurate service commitments and control status. Add independent testing or attestations only when the work has actually been completed.

What customers should be able to ask

Evidence, not adjectives.

A

Where does my data go?

Document storage locations, service providers, model boundaries and the exact data involved in optional integrations.

B

Who can do what?

Explain roles, permissions, administrative access and how consequential automated actions are authorized.

C

What happens when things fail?

Make backup, recovery, incident communication and customer responsibilities understandable before they are needed.

Security questions are welcome

Help us design the standard you would expect.

Design partners can share their customer requirements and review Magpy’s planned security boundaries during early access.

Contact security