Tenant isolation
Row-level security covers all tenant tables. Narrow server repositories handle privileged access, and tenant-scoped writes cannot be read, changed, or interleaved by another workspace.
Security · Execution boundary
Pakkawork uses provider-agnostic control-plane architecture, with Google Workspace as the first provider family. Supported contracts enter the execution path; the model proposes an action and deterministic controls decide whether it may run.
Before
Policy decision
No call runs first
2
Critical approvers
Distinct humans
Signed
Evidence ledger
Append-only
Execution route / PW-01
Proposed call → evidenced outcome
Execution controls
Identity, OAuth, secrets, egress, policy, and evidence are enforced by separate server-side controls instead of relying on an agent prompt.
Browser sessions use Supabase Auth. Agent API keys are shown once, stored as sha256 hashes only, and cannot be recovered from their database representation.
Connections use per-tenant OAuth apps and minimal scopes. PKCE protects the handshake, while single-use OAuth state is consumed atomically so it cannot be replayed.
Tokens use AES-256-GCM envelope encryption with a data key wrapped by a key-encryption key. Tokens are never returned to the browser or exposed through MCP.
Supported execution uses a strict host allowlist. Redirects are handled manually, credentials are stripped across origins, and the contract hash is re-checked immediately before execution.
Risk is computed from the API shape and actual arguments. The required approval threshold is pinned to the request, and critical actions need 2 distinct approvers.
The ledger is append-only and signed. Limited Use redaction keeps content out of retained evidence, while durable jobs and atomic RPC transitions prevent half-applied control states.
Security boundaries
Row-level security covers all tenant tables. Narrow server repositories handle privileged access, and tenant-scoped writes cannot be read, changed, or interleaved by another workspace.
22 live contracts verify results with real API read-back. The other 533 published contracts are generated and unchecked, so Pakkawork does not present them as verified.
Pakkawork records control decisions and signed evidence. Those records support a governance review; they do not certify an organization or replace its own assurance process.
Read the full Privacy Policy and Terms of Service. Questions about architecture, controls, or a security review can be sent to admin@pakkawork.com.