Encrypted in transit, encrypted backups. Strict tenant isolation. Candidate code runs in sandboxed Docker containers with no network access. Every claim on our Trust Center maps to live code or operational practice.
TLS 1.2+ in transit. Backups encrypted client-side with AES-256 before they leave the host.
Every tenant-scoped query carries an explicit company_id predicate. Cross-tenant lookups return 404 rather than 403, so record IDs cannot be probed across accounts.
Candidate code runs in Docker containers with no network, read-only filesystems, seccomp profiles, and resource limits.
Short-lived JWTs, optional TOTP 2FA with device fingerprinting, role-based access control, and Turnstile bot protection on public forms.
We're transparent about where we are. Full details, including subprocessors and data flows, live in the Trust Center.
EU data residency, 4-category cookie consent, DSAR support.
Payment data handled by Stripe. We never see card numbers.
We can complete security questionnaires (SIG Lite, CAIQ-Lite) on request.
Many underlying controls are already in place.
The Trust Center has every technical control, our subprocessor list, incident response procedure, and how to request our DPA or a completed security questionnaire.