Mailionaire
Pax8-first setup + MCP reference
Trust artifact

Security Overview

Private-alpha security posture for bearer auth, secrets, audit trails, and the narrow public surface.

Alpha-ready summary

Current position

Public alpha surface is intentionally small: customer page plus MCP endpoint.
Customer bearer tokens are vendor-issued in alpha and stored hashed at rest.
Customer operational secrets are stored encrypted, scoped to the customer, and never mirrored into customer-visible artifacts.
Every state-changing action emits an append-only audit_log record with actor and object identifiers.