Minimum provider permissions
Connections request the inventory and lifecycle metadata needed for read-only correlation. LintCycle does not request destructive capabilities for a future it has not shipped.
Security
LintCycle is built to explain preview-resource lifecycle drift without gaining the capability to clean it up for you. That boundary is part of the product, not a dashboard setting.
Version-one boundary
Security model
Connections request the inventory and lifecycle metadata needed for read-only correlation. LintCycle does not request destructive capabilities for a future it has not shipped.
Organization access comes from authenticated membership, never a browser-supplied organization identifier. Tenant-owned database work runs inside the tenant context.
Tenant tables enforce organization isolation in PostgreSQL so the data boundary is not dependent on route-handler discipline alone.
Credentials stay out of browser bundles, API responses, background-job payloads, fixtures, logs, and audit records. Provider execution loads them inside the server boundary.
Environment values, API inputs, webhook payloads, and job data are parsed against explicit schemas before the application trusts them.
A finding carries its evidence and rule. The final provider action remains visible, deliberate, and governed by the provider's own authorization.
Data path
This site is static. It has no provider credentials, Stripe keys, price IDs, organization identifiers, tenant API calls, account forms, or server runtime.
Report a concern
If you believe you have found a security or privacy issue, email support@lintcycle.com. Include enough detail to reproduce the issue, but do not include provider credentials or customer data.
Close the loop
Connect the providers you use through an authenticated, tenant-scoped, read-only product boundary.