Back to home

Security

Last updated: June 8, 2025

DevStory is built for teams that need reliable access controls and a clear separation between organizations. This page summarizes our security practices at a high level.

Authentication and access

DevStory uses a dedicated authentication provider for sign-in, session management, and organization membership. Access to protected application routes requires a valid authenticated session.

Enterprise customers may configure SSO through their identity provider where supported.

Workspace isolation

Each workspace operates as a separate tenant boundary. Integration credentials, project data, and billing context are scoped to the workspace that authorized them.

Integrations

Third-party integrations are connected only after explicit authorization by a workspace member with sufficient permissions. DevStory accesses the minimum data required to provide linking, timelines, and insights described in the product.

Infrastructure

We apply industry-standard practices for transport encryption, secret management, and operational monitoring. Production environments are separated from development and testing where feasible.

Reporting issues

If you discover a security concern, contact Oleksandr Romanyeyev promptly at oleksandr@freeskycom.com with sufficient detail for us to investigate.