Appearance
Security and data
This page lists behaviors that run in the live product.
It does not invent retention days, a deletion portal, or a customer audit-log screen.
Sign-in
The dashboard uses PropelAuth.
You sign in with the email an admin stored on Users.
Lab auth bypass is not a customer sign-in method.
Roles
The Users form can assign admin, user, viewer, manager, and analyst.
Only these roles can change Configurations, Alerting, and Users:
adminadministratorsupportsupport_admin
Other signed-in users see View only on those pages.
You cannot change your own role.
Data you enter
On Configurations you store:
- Domains and keywords
- Integration match rules (host, path, or string)
- Vendor name, domain, and critical flag
On Users you store name, email, phone, and role.
On Alerting you store destination type, label, endpoint URL, and rule thresholds.
Secrets
Exposures are secret-level rows (type, file, repository, severity).
The exposure list can show file preview context.
Alert webhooks do not include the recoverable secret value.
See Alerting.
Secret values can be stored with Vault transit encryption when that mode is on for the tenant.
When that mode is off, the customer API stores the value without transit.
Alerts
A matching report sends HTTP POST to your destination.
HTTP status below 400 counts as success. Other results record failure.
Delivery is stored as an alert event (sent, partial, or failed).
The live sidebar has no Alert events page.
API request log
The customer API writes an audit row for /v1/ requests.
A row includes actor, path, method, status, duration, client IP, user agent, and request id.
Health and docs paths are skipped.
There is no Audit page in the dashboard sidebar.
What this page does not claim
- A published retention period
- A self-serve delete-all-my-data flow
- SSO products other than PropelAuth sign-in
- That a vendor grade is an impact decision