Provider-native authorization
Use OAuth or a provider-approved delegated flow. CalendarFuse should never ask a user to send a Google, Microsoft, or Salesforce password.
Trust center
Clear statements about what exists today, what production integrations require, and what CalendarFuse does not claim.
Production requirements
These controls are the security bar for enabling real calendar connections in the private beta.
Use OAuth or a provider-approved delegated flow. CalendarFuse should never ask a user to send a Google, Microsoft, or Salesforce password.
Request only the scopes required for the enabled workflow, explain them before consent, and separate read-only access from event editing.
Keep provider tokens out of browser storage and source control, encrypt sensitive secrets at rest, and restrict backend access by service role.
Executives and administrators control who may view private details, edit events, resolve duplicates, and manage provider connections.
Record actor, action, time, source, and affected record for assistant changes and automated synchronization decisions.
Track provider record IDs and CalendarFuse ownership metadata so an update is not repeatedly copied from one calendar into another.
Disconnecting a provider invalidates its connection. Account deletion has a documented workflow and removes active service data after verification.
Security reports go to support@calendarfuse.com for triage, containment, provider revocation, remediation, and customer communication as appropriate.
Data boundaries
The product design does not rely on selling calendar content or using it for behavioral advertising. Google-connected data is subject to Google's API Services User Data Policy, including Limited Use requirements.
Tuesday · 3:00–4:00 PM
Assistant viewThe executive can grant more visibility for specific assistants, calendars, or event categories.
Report a concern
Send a concise report with the affected URL, reproduction steps, impact, and a safe contact method. Do not access another person's calendar or data while testing.