Design partner security boundary
Security
Delivery Arc is being piloted as a review-first delivery system. Production contact data must not be introduced until the agreed tenant, access, storage, retention, and incident controls are active.
Read-only first
Portal audits are designed around minimum required read access. Consequential recommendations remain proposals for a human reviewer; the current pilot does not promise automatic workflow editing or uncontrolled CRM writeback.
Credentials
HubSpot OAuth credentials, private-app tokens, and provider secrets must be stored server-side and excluded from browser storage, source control, screenshots, support messages, and this public website.
Data minimisation
Configuration evidence should be used instead of contact-level data whenever it can answer the audit question. Pilot inputs, outputs, and retention are agreed before a production portal is connected.
Human review
Findings retain source evidence, confidence, and review state. Accept, reject, and override decisions remain visible. Missing access is reported as a coverage gap rather than silently converted into a portal finding.
Report a concern
Send security concerns to jay@assemblygrowth.com. Do not include credentials, tokens, contact exports, or sensitive client records in the first message.