Product Security Practices
These are the security and access patterns reflected in the application today. For formal compliance reports, penetration test results, or a completed security questionnaire, contact us before procurement.
Tenant-aware architecture
FeatureShark is built as a multi-tenant application with tenant-aware routes, APIs, and data access patterns.
Role and permission controls
Teams can use plan-supported admin seats, built-in roles, custom roles, and permissions to control who can manage feedback, roadmaps, changelogs, support, and settings.
Plan-based feature access
Feature gates limit access to advanced capabilities such as private boards, custom statuses, custom fields, user segments, AI credits, white label, and integrations.
Secure authentication flow
The app uses authenticated admin routes, verified users, and session-based access controls for workspace management.
Public widget boundaries
Widget APIs are separated from admin APIs so public support, survey, changelog, help center, and feedback collection flows do not require admin access.
Managed domains and storage
Custom domains, uploaded files, storage usage, and generated domain configuration are managed through dedicated services and plan limits.
Before a security review
If your team needs a vendor review, the most useful starting point is the exact FeatureShark setup you plan to use. We can then answer questions against your plan, domains, integrations, and AI usage.
- Workspace access model and admin roles
- Data retention and export expectations
- Custom domain requirements
- Integration access for GitHub, Slack, Jira, Linear, or Monday.com
- AI feature usage and credit controls
- Security questionnaire or vendor review requirements
Reporting security concerns
If you believe you have found a security issue in FeatureShark, contact us with the affected workspace, reproduction steps, and impact. We review security reports directly and will coordinate remediation based on severity.
Contact security