Security update: roles, single-use invites and page history
We ran a penetration test and a full acceptance test before opening the doors. Here's what changed: owner roles, single-use invites, sign-out everywhere, rate limits and a restorable history for every page.
Before we open Groundtruth to more teams, we ran a penetration test and a full user acceptance test against it. Everything they found is fixed. Here's what you'll notice.
Owners and members
Workspaces now have owners. Only owners manage API keys, the workspace AI key, alert webhooks, invites and members. Owners can promote a member, step down (as long as one owner remains) and remove people. Removing someone also revokes their API keys and Claude connections.
Single-use invites
An invite link now admits one person and expires after 7 days. Settings shows every open link with a Revoke button.
Signing out means signing out
Logging out, or changing your password, now signs you out on every device. Changing your password keeps the session you're using.
Every edit can be undone
Each page keeps its last 10 versions. Open History on any page to see who changed it, person or agent, and restore an earlier version in one click. Agents can't empty a page, can't pose as a person and can't mark their own work as done.
Under the hood
- Rate limits on sign-in, sign-up, the waitlist, connector sign-in and AI answers, so no one can guess passwords or run up your AI bill.
- Protection against cross-site requests on every action that uses your session.
- Webhooks and connector lookups can only reach the public internet, never internal addresses.
- Stricter browser security headers, including a Content Security Policy.
- API keys are accepted only in the
Authorizationheader, never in URLs where they could leak into logs.
If you find a security issue, email hello@groundtruthhq.tech with "Security" in the subject. We read everything.