Security

How we secure the platform that secures you.

Security is not a checkbox. Below is what we do — encrypted data planes, separated duties, audited controls and a real disclosure program.

Compliance

Where we are. Where we're going.

SOC 2 Type II — audit in progress

Type II audit in progress. Controls aligned with SOC 2 practices, under review.

ISO 27001 — certification planned

Aligned with controls. Formal certification targeted within 12 months.

GDPR

EU-hosted option. DPA available. Data subject rights honored within statutory windows.

Controls

Data protection.

Application security

How we ship code.

Disclosure

Found something? Tell us.

Email [email protected] with details. PGP key and policy at /.well-known/security.txt. We acknowledge within one business day and triage within five.

Trust, in plain terms.

A security product has to earn trust before it earns a deployment. This page describes how we protect the platform and your data: encryption in transit and at rest, isolation between tenants, least-privilege access, audit logging and a development lifecycle with regular security testing.

If your evaluation needs more detail — security questionnaires, documentation or a conversation with the team — contact us and you will get specifics, not marketing. You can also review how the platform is structured.