Security
This page describes how Othersmind (operated by NUL TECHNOLOGY, 202603148027 (003857548-W)) actually protects customer data. Every control listed here exists in the running code today. We also say plainly what we have not built yet — we would rather publish an honest gap than a claim we cannot defend.
Access and authentication
- Google Sign-In with a fail-closed allow-list. There is no password database to breach — sign-in is via Google. An account can sign in only if its email address (or domain) is on an explicit allow-list; if the list is empty or an address is not on it, sign-in is refused. Nobody is allowed by default.
- Project-level access control. Every request is checked against project membership: users can only reach data for projects they are members of, with role-based permissions enforced at the API layer, not just in the interface.
- Hardened OAuth flows. The Gmail-connect flow uses cryptographically signed (HMAC-SHA256) state tokens bound to the initiating user, expiring after 10 minutes, verified with timing-safe comparison — protecting against forged or replayed authorisation callbacks.
- Timing-safe credential checks and rate limiting. Internal service credentials are compared with constant-time methods to prevent timing attacks, and API endpoints are rate-limited.
- Session security. Sessions use an HTTP-only cookie (inaccessible to page scripts). In production the server refuses to start with an insecure fallback signing secret.
Gmail: least privilege by design
- Read-only scope, nothing more. Othersmind requests only
gmail.readonly. It cannot send, modify or delete email — the capability does not exist in the platform, so it cannot be abused, even if an account were compromised. - Metadata-only sync. Messages are fetched in metadata format: headers and Gmail's short snippet. Message bodies are never read; attachments are never downloaded.
- Limited Use. Our use of Google user data follows the Google API Services User Data Policy, including the Limited Use requirements — no ads, no sale, no AI-model training. See the Limited Use disclosure in our Privacy Policy.
- Revocable at any time. Customers can revoke Othersmind's access from their Google Account settings, which immediately invalidates our tokens.
AI agents: human approval before any external action
- Agent-prepared email drafts are created in a "pending approval" state for human review — and the platform has no capability to send email at all.
- Agent-prepared purchase orders are created as draft records only; issuing them is a human decision.
- No agent modifies claim records — agents raise suggestions and notifications for the customer's team to act on.
- Agent LLM usage is metered daily, with configurable hard per-run and per-day call ceilings that fail closed when reached — limiting the blast radius of any malfunction.
Data protection
- Encryption in transit. All traffic — browser to app, app to Google, app to LLM providers — is encrypted with HTTPS/TLS.
- Secret redaction in logs. Authorisation headers, cookies, and OAuth access/refresh tokens are automatically redacted from server logs before they are written.
- Managed infrastructure. The application and MySQL database run on Railway (US); the web layer is served by Vercel. We rely on their managed platform protections for physical and network security, and say so plainly rather than restating their certifications as our own.
- Minimal AI exposure. Only what an agent needs is sent to the LLM provider (for email classification: subject, snippet and sender — never bodies or attachments, which we do not hold). Our providers' terms prohibit training on our data by default; see Privacy Policy §7.
What we are still building
We publish this list because honest gaps protect customers better than claims we cannot defend:
- Encryption at rest for OAuth tokens. Stored Gmail OAuth tokens are protected by access controls, transport encryption and our database provider's managed protections, but are not yet encrypted at the application level. This is on our engineering roadmap. Customers can invalidate stored tokens at any time by revoking access in their Google Account.
- Formal tenant isolation. Customer data is separated by project-level access control within a shared database. Formalised per-tenant isolation is planned as the customer base grows.
- In-product deletion and automated retention. Deleting synced email data currently requires an emailed request (see Privacy Policy §12); automated retention schedules beyond our 90-day agent-findings purge are planned.
We do not hold ISO 27001, SOC 2 or similar certifications, and we make no compliance claims we cannot verify.
Reporting a vulnerability
If you believe you have found a security vulnerability in Othersmind or othersmind.ai, please email chiewaylee@gmail.com with the subject line "SECURITY". Include steps to reproduce and, if possible, the affected URL or endpoint.
- We will acknowledge your report within five (5) business days and keep you informed as we investigate and fix.
- Please act in good faith: do not access data that is not yours, do not degrade the service, and give us a reasonable opportunity to fix the issue before public disclosure.
- We do not currently operate a paid bug bounty, but we are grateful to researchers and will credit you if you wish.