WickArk / security
Security boundaries, not security slogans
How WickArk separates public product pages, authorized workspaces, and private research.
Workspace access is enforced on the server
Authentication and workspace membership checks protect research APIs. Knowing a resource identifier or hiding a browser element is not authorization. Public demo data is isolated from customer records.
Private research stays behind an explicit boundary
Customer-facing scenario responses use sanitized public fields. Private feature recipes, model weights, credentials, storage keys, and sealed holdout results do not belong in public responses. Ordinary workspace ownership does not grant private Research Core access.
Claims we do not make
These are implemented design controls, not a claim of an independent penetration test, SOC 2 certification, zero risk, or guaranteed uptime. The public demo performs no research mutation, model training, or brokerage action. Security and release reviews remain distinct from product capability.