Security
4 min
The EAI enforces multiple layers of security to protect your data and ensure safe system-to-system communication.
Transport Security
- HTTPS only — All API requests must be made over HTTPS. Plain HTTP requests are rejected.
Access Control
- Tenant isolation — Each EAI account is bound to a specific company tenant. Cross-tenant access is not possible. An account provisioned for acme.teleskope.io cannot access data on globex.teleskope.io.
- Module scoping — Each account is scoped to a specific module (Graph or Uploader). An account authorized for the Graph API cannot access the Uploader, and vice versa.
- Granular permissions — Each account has fine-grained permissions controlling which endpoints it can access. Unauthorized requests return 403 Forbidden.
Available Permissions
Permission | Description |
|---|---|
get_zones | List zones by application type |
get_groups | List groups within a zone |
get_group_chapters | List chapters within a group |
get_group_channels | List channels within a group |
get_members | List members in a group, chapter, or channel |
get_leads | List leads in a group, chapter, or channel |
get_events | List events within a scope |
get_audit_logs | Retrieve membership audit logs |
get_user | Look up a single user |
get_all_users | List all users (paginated) |
create_user | Create a new user |
update_user | Update an existing user |
post_user_data_sync | Upload user data for sync (Uploader) |
post_user_data_delete | Upload user data for deletion (Uploader) |
Network Security
- IP whitelisting — Optionally restrict API access to specific IP addresses or CIDR ranges. When configured, requests from non-whitelisted IPs are rejected with 403 Forbidden. Contact your Teleskope administrator to configure allowed IPs.
Rate Limiting and Abuse Prevention
- Rate limiting — Certain endpoints (e.g., getAllUsers) include built-in rate limiting to protect platform stability.
- Token limits — OAuth2 accounts are limited to 10 active tokens to prevent credential abuse.
Monitoring
- Audit logging — All EAI requests are logged for security monitoring and troubleshooting. Logs include the authenticated account, endpoint called, request parameters, and response status.