Account security
Two-factor authentication
Every member can enable TOTP two-factor authentication (any authenticator app) with one-time backup codes, from Settings → Security. Sign-in for enrolled accounts requires the second factor.
Session control
Review every active session — device, network, age — and revoke any one of them (or all others at once) from Settings → Security. Sessions expire after 7 days.
Credentials and keys
Encrypted at rest
OAuth tokens and secrets are encrypted at rest with AES-256-GCM, with support for master-key rotation. LivingContext never stores your git or Salesforce credentials in plaintext.
Hashed API keys
API keys — extension keys and MCP keys — are stored as hashes and shown once at creation. Keys can be minted with an expiry (30/90/365 days), and creation and revocation are recorded in the audit log.
Organization security policy
Administrators set org-wide access policy in Settings → Security:Audit log
Beyond the agent action trail, every security-relevant event in the organization is recorded append-only — sign-ins across all providers, member and role changes, invitations, API keys, connections, and settings edits, each with actor, IP address, and timestamp. Administrators review and filter it in Settings → Audit log; retention follows your policy.Tenant isolation
Each organization lives on its own subdomain (<slug>.livingcontext.ai) with per-organization data isolation. Members of one organization can never see another organization’s docs, connections, or activity.
Your data
- Export — any member can download a JSON export of everything stored about their account (profile, linked sign-in providers, memberships, sessions, key metadata — never secrets) from Settings → Security.
- Deletion — self-service account deletion, with a safeguard: the last administrator of an organization with other members must hand over administration first.
What agents can and cannot do
Reads are minimized
When agents ground documentation against your live Salesforce org, they work from metadata, not record contents. For example, field utilization analysis is count-only — the agent learns how many records populate a field, never what’s in them.Writes are gated
Every side-effecting agent action — a Salesforce write, a deployment, an outbound call — requires explicit human approval before it runs, on every plan. There is no configuration that removes the approval gate.Everything is auditable
Every side-effecting agent action is written to an immutable audit log, so you can always answer who approved what, and when.Documentation changes follow the same principle: agent-drafted docs ship only through human review in the Inbox, a change request, or a PR. See Core concepts.
Browser capture safety
The capture extension is designed so sensitive data never leaves the browser in the first place:- Redaction happens at capture time, not after upload. Configurable smart-blur categories (see the settings reference) are applied as the capture is recorded.
- Passwords are always masked, regardless of your blur settings. This floor cannot be turned off.
- Screen recording is constrained to the browser tab only — the extension cannot record your full screen or other application windows.
Sign-in options
You control how your team authenticates:- Email and password (with optional two-factor), Google, or GitHub
- Enterprise SSO through your identity provider — Okta, Microsoft Entra, Auth0, and other standards-based IdPs
Security checklist for administrators
1
Turn on two-factor authentication
Enable 2FA on your own account first (Settings → Security), then ask administrators and creators to do the same.
2
Set the organization policy
Restrict invitations to your email domains, and add an IP allowlist if your team works from known networks.
3
Right-size roles
Default invitations to Editor, and reserve Administrator for the few people who manage members and billing.
4
Review keys periodically
Extension and MCP keys are listed in Settings — prefer expiring keys, and delete any that are no longer needed. Offboarding revokes a departing member’s keys automatically.
5
Tune capture blur
Review the smart-blur categories in Settings so captures redact the data classes your organization cares about.
6
Make the audit log part of your cadence
Check Settings → Audit log for sign-ins, role changes, and key activity as part of your regular review.
On the roadmap
Being transparent about what’s not built yet:
If one of these gates your security review, contact us — they’re prioritized by enterprise demand.