SemantiqWall
PT EN
Sign in I'm a vendor

← Trust Center

Access Control and Identity

Version
1.0
Owner
Founder
Approved by
Murilo Martins (Founder) · 09/28/2026
Next review
2027-09-28 (annual or on significant change)
Scope
Accounts on the SemantiqWall platform (customer users, platform reviewers, API keys), the production server, the database, the code repository and every supplier account used to run the service.

1. Principles

2. Platform users (in place)

3. Roles inside a customer organization (in place)

Role Can do
Owner Everything in the organization, including members and settings
Admin Configure agents, tools, policies and keys; cannot approve agent actions by default
Approver Approve or deny agent actions; cannot change policies
Analyst Work on cases and read decisions
Viewer Read only

Permissions are checked on every request. Every tenant query is scoped to the current organization and throws an error instead of returning data when no organization is set; this is covered by automated tenant-isolation tests.

Platform reviewers (is_platform_admin) can review vendors but never a vendor they are linked to.

4. API keys (in place)

5. Privileged and server access

In place today (verified on the server):

In rollout: separate database roles so that the application role cannot alter or disable the append-only audit table (owner: Founder, target 2026-10-15).

Commitments:

6. Supplier and tool accounts

The Founder's accounts at GitHub, Hostinger (VPS panel), Resend, GoDaddy (Titan mailbox and domain registrar) and any AI provider must have MFA enabled and a unique password stored in a password manager.

Status: to be verified. Commitment: confirm MFA on each account, record the evidence in the security register (owner: Founder, target 2026-10-15).

7. Provisioning and de-provisioning

8. Access reviews

Starting in Q4 2026 and then every quarter, the Founder reviews and records in the register:

Anything not justified is removed. First review: owner Founder, target 2026-10-31.

Customers are responsible for reviewing their own members and API keys (policy 11).

9. Secrets