We hold your most sensitive business and personal data. Here's exactly how we protect it — and how you can verify our claims.
Controls
TLS 1.3 for data in transit. AES-256 for data at rest. Keys rotated quarterly and managed via a hardware security module.
MFA required on every employee account. Customer accounts support TOTP and WebAuthn passkeys.
U.S.-only data centers with SOC 2 / ISO 27001 hosting partners. Private VPCs, no public database exposure.
24/7 SIEM with automated alerting. Anomaly detection on logins, data access, and API behavior.
Role-based access controls. Quarterly access reviews. Just-in-time elevation for production systems.
Tested playbooks, on-call rotation, and contractual breach notification within 72 hours where applicable.
Operational practices
Responsible disclosure
We welcome reports from independent security researchers. Submit findings to [email protected] with steps to reproduce. We acknowledge within 24 hours and triage within 3 business days. Acting in good faith and within scope, we will not pursue legal action.
SOC 2 Type II report, penetration test summary, and security questionnaires are available to customers and partners under NDA.
Request documents