SECURITY

Company access is scoped, authenticated, and controlled.

Morrow uses authenticated access, company membership controls, and isolated company records to limit information to authorized users. This page describes current, app-visible controls and does not claim independent certification.

Authentication
Verified access to every workspace.

Access requires an authenticated account. Sessions and credentials are managed through the platform's authentication layer.

Company membership and roles
Access is scoped per company.

Company membership determines which workspaces a user can see. Role and permission checks are enforced server-side.

Tenant isolation
Company records stay isolated.

Company records are isolated by workspace. Row-level policies are used where applicable so authorized users see only their own company's data.

Audit history
Consequential actions are recorded.

Consequential actions — approvals, decisions, and record changes — are captured in the company's audit history.

Security contact
Report a security concern.

Contact support@meetmorrow.ai for security or vulnerability reports. Include reproduction detail and impact where possible.