Trust center · Privacy

Customer context stays bounded by purpose and audience.

The Workspace separates public intake, client-visible delivery context and Wythin-only engineering records instead of treating every field as equally shareable.

Last updated
25 August 2026
Status
Architecture and operating principles

Data boundaries

WythinForge stores relationship and delivery metadata: organizations, requests, messages, attachments, estimates, decisions, previews, releases, owners and next actions. Operational transaction data remains in the customer systems that own it.

  • Internal engineering references, internal messages and internal files remain outside client-readable projections.
  • Attachments remain private and are exposed through signed, expiring URLs after authorization checks.
  • Telemetry allowlists exclude request text, file contents, e-mail addresses, company names and authentication tokens.
  • Optional analytics, browser diagnostics and external embeds are disabled until the visitor grants the corresponding consent category.

Control and accountability

Significant mutations produce append-only activity. Immutable estimate decisions and versioned delivery artifacts keep later changes distinguishable from the record a customer reviewed.

The legal privacy notice describes processing purposes, legal bases and data-subject rights. Contract-specific retention and processor terms belong in the applicable agreement and DPA.