Security follows the agreement boundary.

Organization roles limit operator access. Scoped links limit participant access. Material actions retain their source, actor, time, and result.

Controls you can verify in the product and contract.

Your own security, legal, and vendor review still applies.

Access and retained records

Organization-scoped access

Each app session resolves a verified organization membership and role. API tokens belong to one organization member, expire within 90 days, and carry explicit scopes.

Protected file delivery

Retained files use short-lived, scoped download links. Signing and investor links expose only the assigned agreement or investment work.

Material events remain attributable

Approvals, movement evidence, reconciliation, exceptions, and completion records retain the actor, time, and result instead of rewriting prior events.

Providers and operational boundaries

Bank credentials stay with the bank

Customers send funds through their own bank or provider. Termn keeps authorization, sender report, receipt evidence, and reconciliation distinct.

Billing uses hosted checkout

Stripe Checkout and the Stripe Customer Portal handle Project Pass and subscription billing. Browser input does not choose the catalog item or amount.

Failed work remains visible

Readiness checks cover data storage, file delivery, document rendering, billing, and email delivery. Blocked work, exhausted retries, failed email, and failed webhook delivery remain visible to authorized operators.

Review the controls that apply to your integration.

Authenticated trust, SAFE, private-loan, and general agreement workspaces use organization and participant scope. The API reference documents roles, token scopes, request rules, and webhook guarantees.