How your filesare kept apart.

What follows is how Gridline is built today, described without adjectives. Where something is missing, it is listed under known limits.

One company’s data is invisible to another.

Every query is scoped to your company, and the company comes from the signed-in person’s own record, never from a URL or a request body. Another company’s file is not forbidden: it is not found.

  • A file you may not see answers 404, exactly as a file that does not exist would.
  • Within a company, a restricted file is visible only to its uploader, the people it names, and admins.
  • Role, status and company standing are read from the database on every request, so removing someone takes effect on their next request.
Two requests, one answer
GET /files/<a file in another company>404 Not found
GET /files/<an id that never existed>404 Not found

Sign-in and sessions.

Passwords are hashed with scrypt and never stored or logged. Sessions use short-lived access tokens and refresh tokens that rotate.

  • Reusing a spent refresh token revokes the whole session family.
  • Changing or resetting a password revokes the person’s other sessions.
  • Sign-in with Google is supported, and the last way to sign in to an account cannot be removed.
  • A wrong password and an unknown email get the same answer, and the same amount of work.

API keys that can only do what you said.

A key acts as the person who created it, and never with more than that person’s role or the scopes chosen for the key. The key is shown once; only a hash is stored.

  • Keys are denied by default: a route is reachable by a key only when it explicitly allows one.
  • A key cannot create keys, invite people, change a plan or read the audit log.
  • Removing a person revokes their keys.

Files stay private.

Uploads go to a private bucket. A download link is minted only after the access check and expires after five minutes.

  • The type of a file is decided from its bytes, never from its name or declared type: an executable renamed .csv is refused.
  • A refused or failed upload stores nothing and uses no quota.
  • The optional AI summary is built from aggregate statistics only. It is never shown a row or a cell value.
  • A file nobody points to any more (an upload that crashed half way) is removed by a daily sweep.

Personal data is found, not guessed.

Each report lists the columns that look like email addresses, phone numbers, card numbers, IBANs, IP addresses, birth dates or secret keys. It is decided by patterns and checksums in Gridline itself. No AI is involved and no value ever leaves the file.

  • A card number must pass the Luhn check and an IBAN its checksum, so an order number is not reported as a card.
  • The report says which column and what kind, never a value.
  • A file with personal data that the whole company can open tells its uploader and your admins, and can fail a rule you set.
  • Cleaning can hide a column: all of it, the last four characters, or a keyed fingerprint that cannot be reversed.

The assistant answers from names, not rows.

A summary or a question is written by a model from column names, types and statistics. The model plans a query; Gridline checks it and runs it on the file itself, and the answer never goes back to the model.

  • A question and the column names are the only free text the model is given, and are passed as data, never as instructions.
  • What the model returns is validated against the same rules as a query you build, so it can do no more than the builder can.
  • Who can ask is who can see the file: a file you cannot see is not found.
  • Questions are counted against the plan. The builder, which uses no model, is not.

A record that cannot be edited.

Every state change is written to the audit log in the same transaction as the change, and the database rejects any update or delete of that table.

  • Entries record who acted, on what, when, and from which key if one was used.
  • Admins can filter the log and open any entry.

Signed webhooks that cannot be turned on you.

Every delivery is signed with HMAC-SHA256 over its exact body, so your endpoint can verify it. Secrets are shown once and stored encrypted.

  • Deliveries resolve DNS on every attempt and refuse private, loopback and reserved addresses, so a webhook cannot be aimed at an internal service.
  • Redirects are never followed.
  • Only admins, through a signed-in session, can create endpoints. An API key cannot.

Payments belong to Stripe.

Card details are entered with Stripe and never touch Gridline. Stripe’s notifications are verified by signature and processed once each, whatever order they arrive in.

  • A plan changes from a verified Stripe event, not from a request to Gridline.
  • A failed payment starts a grace period before a company is suspended.

Limits that follow the plan.

Each plan has a request budget shared by the whole company, so one busy integration cannot starve the others. Sign-in, password reset and similar routes have small limits of their own.

Known limits, and what we do not claim.

Gridline has not been through a SOC 2 or ISO 27001 audit and does not claim any certification. These are the gaps we know about.

  • Realtime updates and request limits run on a single API instance today, so they are not shared across servers.
  • There is no self-service company deletion or data export yet.
  • Personal-data detection is by pattern. A column of names or addresses written as free text is not recognised, so a clear result is not a guarantee.
  • Rotating a webhook secret has no overlap period, so a delivery in flight when you rotate is signed with the new secret.