Tenant isolation
Every business record is scoped to an organization and authorization is enforced on the backend, not merely hidden in the UI.
ActionNudge is being engineered with security controls from the foundation layer, including tenant isolation, secure authentication, auditability, minimal OAuth permissions and human oversight of sensitive AI actions.
Security questionsEvery business record is scoped to an organization and authorization is enforced on the backend, not merely hidden in the UI.
Owners, administrators, managers, sales agents, service agents and viewers receive only the capabilities their role requires.
Gmail and Microsoft integrations use provider OAuth. ActionNudge never asks users for their email passwords.
Sensitive changes, approvals, integrations and administrative actions are designed to produce traceable audit events.
Structured AI outputs are validated. Business rules determine permissions, financial thresholds and when human approval is mandatory.
API keys, OAuth secrets, database credentials and encryption keys stay server-side and outside frontend bundles.
For example, an AI model might recommend reviewing a $500 refund. If company policy requires manager approval above $50, ActionNudge must enforce the rule regardless of the AI recommendation.
The architecture is being designed with privacy and security requirements such as GDPR, PIPEDA and CCPA/CPRA in mind. ActionNudge will not claim certifications or formal compliance status until the required legal, technical and audit work has actually been completed.
Early customers can bring their security and privacy questions directly to the team.
Talk security