Security

Deny by default, revoke immediately

Gatehouse mitigates stolen links with sign-in, short-lived session capabilities, method-scoped grants, connector identity, audit logging, strict service targets, and revocation propagation.

SSRF metadata blocks
No sensitive bodies in audit logs
Secure cookies and CSP headers
Tenant-scoped data model