Security-conscious architecture

Control and Separation by Design.

RETURNER is designed to protect account boundaries, provider connections and access between Builders and Agencies.

Secure authentication

Account access follows a secure authentication and HttpOnly session model.

Role-based access

Permissions are scoped to a user’s role and authorized context.

Tenant isolation

Builder and Project boundaries help keep customer data separated.

Controlled Agency access

Builders control assigned, read-only Project visibility.

Protected credentials

Provider credentials are designed to be encrypted and handled with care.

OAuth connections

Provider access uses OAuth authorization where supported.

Audit logging

Security-relevant activity can be recorded for operational review.

Safe navigation

Redirect destinations are validated to reduce unsafe routing.

Data minimization

The platform aims to process only information needed to provide the service.

No certification or compliance badge is implied on this page. Security controls evolve with the service and deployment environment.