Workspace isolation
Authentication and team membership are enforced server-side. Every read and write is scoped from the active signed-in identity—not from an identifier supplied by the browser.
Private source handling
Uploaded files live in private object storage. StoryIQ preserves source metadata and evidence pointers so claims remain auditable.
Payment separation
Checkout, cards, invoices, and subscription changes are handled by Stripe. StoryIQ stores billing identifiers and status, never card details.
Offboarding controls
Members can leave, admins can remove workspaces and organizations, and users can delete their account from inside the product.