Organization is the boundary
Active membership and verified parent ownership are required for customer resources. A browser-supplied organization or role is never authoritative.
Security model Current product controls
MessageHop uses organization isolation, scoped credentials, server-side authorization, separate trust zones, immutable evidence, and fail-closed product behavior. This page describes implemented product controls; it does not claim a certification or universal guarantee.
Active membership and verified parent ownership are required for customer resources. A browser-supplied organization or role is never authoritative.
Customer server secrets are shown once and stored as verification material. Provider credentials use managed secret storage.
Protected operations evaluate identity, action, resource, scope, active state, recent sign-in, MFA, and command context as required.
Routine support does not imply platform administration. Privileged sessions are permission-gated, TOTP-backed, and time-bounded.
Idempotent acceptance, bounded dispatch, immutable ledger events, price snapshots, and reconciliation protect against duplicates and silent rewrites.
High-impact workflows require reason, audit, recent authentication, MFA, and a different reviewer where two-person approval applies.
Customer replies and internal notes are separate backend states. Attachments use ticket-scoped authorization and safe metadata.
Hosting denies framing, restricts browser capabilities, prevents console indexing, and keeps public REST routes explicitly bounded.
Email security@msghop.com with safe reproduction steps and impact. Never include credentials, customer message content, or unnecessary personal data.