Documentation

Security and your data

Understand workspace access, secrets, files, AI providers, and deletion.

Use this page to decide what belongs in Appaca and who should have access.

The workspace is the boundary

Apps, Data, Storage, Knowledge, Connectors, and Coworkers belong to a workspace. Members can open only the apps and Coworkers on their access lists and cannot browse Data or Storage.

The one exception is the roadmap, which is deliberately public across all of Appaca. Anything you post there is visible to everyone using the product.

Where to put secrets

Use these product fields for sensitive values:

  • Configs for values used by one app
  • Connectors for supported services
  • Auth Headers when adding an MCP server

Files

Uploaded and generated files are private to the workspace.

Recipients must sign in and have access to the workspace file. Do not use a Storage file URL as a public download link.

Deletion

Deleting an app or workspace is permanent. Review the confirmation carefully before continuing.

Deleting a workspace removes the workspace, its membership, and its invitations. Only the owner can do this, and they must own another workspace.

Download files and save any information you need before deletion. For account help, email [email protected].

Reducing your exposure

The controls that make the most difference in practice:

  • Keep member access lists tight. Grant apps and coworkers individually rather than promoting someone to admin for convenience.
  • Review share links. A Share link can be reachable without workspace membership. Use Require workspace membership or a Passcode when needed.
  • Grant connectors narrowly. Authorize with an identity that has only the access the workflow needs, and assign the connector only to the app or coworker that uses it.
  • Prefer read access for connected agents. Grant broader permissions only when needed.
  • Transfer ownership before an owner leaves.