← All posts
Security

Security update: roles, single-use invites and page history

We ran a penetration test and a full acceptance test before opening the doors. Here's what changed: owner roles, single-use invites, sign-out everywhere, rate limits and a restorable history for every page.

Before we open Groundtruth to more teams, we ran a penetration test and a full user acceptance test against it. Everything they found is fixed. Here's what you'll notice.

Owners and members

Workspaces now have owners. Only owners manage API keys, the workspace AI key, alert webhooks, invites and members. Owners can promote a member, step down (as long as one owner remains) and remove people. Removing someone also revokes their API keys and Claude connections.

Single-use invites

An invite link now admits one person and expires after 7 days. Settings shows every open link with a Revoke button.

Signing out means signing out

Logging out, or changing your password, now signs you out on every device. Changing your password keeps the session you're using.

Every edit can be undone

Each page keeps its last 10 versions. Open History on any page to see who changed it, person or agent, and restore an earlier version in one click. Agents can't empty a page, can't pose as a person and can't mark their own work as done.

Under the hood

  • Rate limits on sign-in, sign-up, the waitlist, connector sign-in and AI answers, so no one can guess passwords or run up your AI bill.
  • Protection against cross-site requests on every action that uses your session.
  • Webhooks and connector lookups can only reach the public internet, never internal addresses.
  • Stricter browser security headers, including a Content Security Policy.
  • API keys are accepted only in the Authorization header, never in URLs where they could leak into logs.

If you find a security issue, email hello@groundtruthhq.tech with "Security" in the subject. We read everything.