Identity
Every key and OAuth token resolves to one organization and one portal user.
A clear view of how Mad Fish Elements protects data, governs access, and operates the services behind every Element.
Every key and OAuth token resolves to one organization and one portal user.
Connection visibility and Read, Write, and Delete grants are evaluated per user.
Credential changes, key rotation, authorization, and synchronization are auditable.
Security controls follow the request from configuration through execution.
Administrators choose available connections, assign user access, configure capabilities, and issue or revoke credentials.
Raw provider secrets are stored in Azure Key Vault. Portal records retain secret names, versions, status, and non-secret configuration.
The gateway hashes the presented bearer or API key, resolves its organization and user, and applies that user's enabled platform and capability map.
Only an enabled tool can call a connected provider, and provider responses return through the same governed request path.
Continue through security, data handling, sub-processors, and the API contract from this Trust Center.