Security
Last updated: June 8, 2025
DevStory is built for teams that need reliable access controls and a clear separation between organizations. This page summarizes our security practices at a high level.
Authentication and access
DevStory uses a dedicated authentication provider for sign-in, session management, and organization membership. Access to protected application routes requires a valid authenticated session.
Enterprise customers may configure SSO through their identity provider where supported.
Workspace isolation
Each workspace operates as a separate tenant boundary. Integration credentials, project data, and billing context are scoped to the workspace that authorized them.
Integrations
Third-party integrations are connected only after explicit authorization by a workspace member with sufficient permissions. DevStory accesses the minimum data required to provide linking, timelines, and insights described in the product.
Infrastructure
We apply industry-standard practices for transport encryption, secret management, and operational monitoring. Production environments are separated from development and testing where feasible.
Reporting issues
If you discover a security concern, contact Oleksandr Romanyeyev promptly at oleksandr@freeskycom.com with sufficient detail for us to investigate.