🛡️
Your data stays in your organisation
No third-party database, no vendor cloud.
- Everything lives in Google Sheets, Docs and Drive files owned by your organisation. There is no database to breach or maintain.
- Each organisation runs its own copy with its own Google Cloud project, so data is never shared between organisations.
- You can inspect, back up or export everything from Drive at any time, and Google's version history helps recover from mistakes.
🔑
Access follows Google Drive permissions
No separate accounts to manage.
- The app calls Google with the signed-in user's own token, so nobody can see or change more than Google already allows them.
- Owners and managers are admins, Editors can change data, Viewers are read-only.
- Revoke access by unsharing the folder in Drive; it applies from the next request. Sign-in can be limited to your own organisation (OAuth “Internal”).
🔒
Sign-in and tokens
Google sign-in only.
- The app never sees or stores your password.
- Google access tokens stay on the server, inside an encrypted, HttpOnly session cookie, and are never handed to the browser's JavaScript.
- Who did what (comments, log, notifications) is taken from the signed-in account on the server, not from what the browser claims.
🧾
Audit trail
See who did what, and when.
- Every create and update is recorded with the user, time and what changed.
- The app only appends to the log. As it is a normal Google Sheet in your Drive, Google's version history still shows any direct edit.
- Filter in the app, download as CSV, or open the Log tab in Google Sheets.
✅
Built for least privilege
Ask for little, protect what you keep.
- Assignment emails are sent from the assigner's own Gmail. Set NOTIFY_EMAIL=false and the app stops asking for the Gmail permission at sign-in.
- Secrets (client secret, session key) live only in the server's .env file, never in the browser or the repository.
- Two people editing at once are detected instead of overwriting each other, and text placed into emails and release notes is escaped.