Transparent security policy
How Caplifi Tech Ops keeps support under control.
This is the readable security posture for Caplifi Care and Tech Ops. It is not a marketing claim of “best security,” and it is not a substitute for product terms.
Who this covers
Caplifi Tech Ops (also called Caplifi Care) is the support organization behind Caplifi product surfaces: help tickets, fulfillment coordination, deploy coordination, and ops pulse. Security here means how support access, tickets, and change power are constrained.
What we protect
- Customer support conversations and account contact data
- Access credentials for customer portals and staff seats
- Ability to fulfill requests and change production systems
- Integrity of audit records for material actions
How access works
- Least privilege. Named seats for care, deploy, agent lead, ops, and principal work. Tools are allowlisted. A care seat cannot mint employees.
- Human dual mode. A person can sit the same seat an agent assists. Authority does not silently expand because AI is present.
- Hard stops on irreversible acts. Secrets, mainnet, factory-reset class actions, and irreversible money paths are not approved by chat alone.
- Material change seals. Significant ships and principal-class acts pass an approval gate.
- One customer channel of record. Customer-visible replies go through Care. Internal staff notes are not the customer record.
- Evidence. Material tool and portal actions are audited so abuse can be reconstructed.
Authentication (current posture)
- Customer portal: token scoped to that customer.
- Staff Tech Ops portal: admin token per seat identity; rotate when share risk rises.
- Agents: only through the seat runtime and registered tools.
We treat tokens as passwords. If a token may have leaked, rotate it.
What we will not do
- Promise response times we have not dogfooded
- Claim public “best-in-class security” without a page you can open
- Ask customers for seed phrases, private keys, or full payment card data in tickets
- Run a second unofficial support desk as the only path for a product
Incidents
If we believe customer data or staff access was abused, we contain (revoke or rotate credentials), notify responsible officers, write a postmortem, and fix the control gap. We do not only narrate.
Verify this page
The machine hash of the house source policy is published below and in version.json. After you read the policy, you can compare hashes. When this page is live on production DNS, the same hash should match.
06f00df7b4e397011a7099e290d95c611035feef4b6304b664bed8e884976f1e
Machine file: /security/policy/version.json
Contact
Product help: Caplifi Support
Security concern: Report a security issue
Email: hello@caplifi.com