Your workspace has an access boundary
The server checks identity and workspace membership. Roles govern editing and administration. Clerk can provide production sign-in, email verification, and recovery; the local development account system does not independently verify email or provide account recovery.
Changes can be inspected
Web AI proposals require explicit apply. Revision checks prevent stale proposals from silently overwriting newer work. Rules validate governed changes, and record versions preserve recent snapshots. These features do not constitute a regulatory certification.
AI use has a provider boundary
Configured AI features send selected workspace context to the provider. Access depends on workspace permissions and explicitly granted sources. Your operator's provider account, settings, and applicable terms determine the external processing arrangement.
Storage has an operator
Ralti supports SQLite for local use or PostgreSQL for hosted deployments. Private attachments use durable server storage. Operators are responsible for infrastructure access, backups, retention, recovery, provider credentials, and the privacy notice appropriate to their deployment.
Current limits are part of the decision
No SOC 2, ISO 27001, or HIPAA certification is claimed. Enterprise SSO/SCIM deployment, per-record permissions, restricted client portals, and end-to-end encryption are not represented as available product guarantees. Review the deployment guide before bringing sensitive business data.