Chickpea’s security model rests on a few rules that are checked in code: credentials never reach the model, conversation cannot expand authority, and consequential actions need confirmation. This section states each rule and the mechanism behind it.
Security model
The guarantees a deployment enforces in code, the mechanism behind each, and the limits. Read it.
Authority and confirmation
Where authority comes from, what applies immediately, and what waits for your explicit approval. Read it.
Data and storage
Where deployment state lives on each target, how credentials are keyed, and retention. Read it.
The shared Slack gateway
What the Chickpea-operated Slack gateway sees, stores, never stores, and how to avoid it. Read it.
Product telemetry
Six anonymous, content-free events, what they never carry, and the total opt-out. Read it.
Recovery
Repair a deployment that can no longer authenticate its own Slack app. Read it.
