Read-only Stripe analytics
MRR Pilot is designed to analyze revenue. The customer Stripe connection is not used to create charges, issue refunds, transfer funds or change Stripe account settings.
Server-side controls
The application uses server-side authorization checks, workspace isolation, application roles, protected admin routes, server-side feature gating and audit logs.
Credential protection
Connected integration credentials are encrypted when stored by the application. Stripe keys and tokens are not displayed in the UI, admin screens or AI prompts.
Beta limitations
MRR Pilot does not claim SOC 2, ISO 27001 or PCI DSS certification for the service. Security controls will continue to be reviewed as the product matures.