Customer isolation
Customer workspace routes require an authenticated session and enforce project ownership. Internal operator surfaces are separate from the customer workspace.
Provider credentials
Connected provider credentials are handled server-side. Customer-facing pages are not intended to contain provider access tokens or production secrets. When a provider connection is absent or invalid, execution should remain unavailable rather than silently bypass the requirement.
Billing and acquisition budget
Stripe-hosted checkout handles card entry. Funding an acquisition budget and being able to spend that budget are separate capabilities. Paid execution remains blocked unless the production spend rail, channel connection, project limits and other required safety checks are ready.
Measured evidence
Public research sources do not count as customer conversions or permission to spend. Changes to a winning strategy require measured or replayable customer-event evidence under the evaluation rules.
Operational safeguards
- production health and readiness checks;
- restart-safe persisted state for important workflows;
- budget and customer-cost limits;
- channel-level execution modes;
- reconciliation before treating paid execution as authoritative.
What Partizan does not claim
This page does not claim SOC 2, ISO 27001, PCI merchant certification, penetration-test coverage or any other certification that has not actually been completed. Stripe handles payment-card entry through its own checkout infrastructure.
Report a vulnerability
Do not post credentials, exploit details or customer data into a normal public issue. Use the repository's private vulnerability-reporting path on GitHub when available. If that path is unavailable, open a minimal public issue asking for private security follow-up without including the sensitive details.