Commercial automation needs explicit boundaries.
Trevra is designed around evidence, least privilege, approval integrity, and auditable execution.
01. Approval integrity
The exact approved GTM payload, including structured action metadata, is hashed before execution. Modified payloads are rejected.
02. Workspace isolation
Application queries are scoped by workspace, authentication data and commercial records use PostgreSQL, and external credentials are delegated to the integration layer.
03. Verified events
Nango integration webhooks and signed GTM capture requests are verified, deduplicated, and processed idempotently.
Responsible disclosure
Report a suspected vulnerability to [email protected]. Include reproduction steps, affected URLs, and the potential impact. Do not access data that is not yours, disrupt service availability, or use destructive testing.
The canonical machine-readable disclosure channel is /.well-known/security.txt.