Company access is scoped, authenticated, and controlled.
Morrow uses authenticated access, company membership controls, and isolated company records to limit information to authorized users. This page describes current, app-visible controls and does not claim independent certification.
Access requires an authenticated account. Sessions and credentials are managed through the platform's authentication layer.
Company membership determines which workspaces a user can see. Role and permission checks are enforced server-side.
Company records are isolated by workspace. Row-level policies are used where applicable so authorized users see only their own company's data.
Consequential actions — approvals, decisions, and record changes — are captured in the company's audit history.
Contact support@meetmorrow.ai for security or vulnerability reports. Include reproduction detail and impact where possible.