Legal

Compliance

What the platform does to protect your data, and where each framework actually stands. We list status, not badges.

Practices

Encryption

Secrets are encrypted at rest with AES-256-GCM envelope encryption. Customer data is encrypted in transit with TLS 1.2 or later.

Tenant isolation

Every query runs under row-level security scoped to the workspace. Cross-tenant reads are blocked at the database, not only in application code.

Audit trail

Who did what, when, and from where is recorded for every privileged action and retained for seven years in write-once storage.

Data deletion

Deletion requests are honoured within 30 days. Right-to-be-forgotten is implemented and tested, not a manual process.

Incident notification

Customers are notified of security incidents affecting their data within 72 hours.

Availability

The uptime objective is 99.9% per service, measured continuously. Enterprise plans carry a written SLA.

Frameworks

FrameworkStatusDetail
SOC 2Controls mappedControl mapping complete; attestation not yet performed.
GDPRAlignedDPA available; subprocessor list maintained; DSAR tooling in the product.
HIPAAControls mappedBAA considered as part of an enterprise security review.
ISO 27001Not certifiedNo certification held.
FedRAMPAlignedControl mappings to NIST 800-53; no authorisation held.

Need evidence for a security review? Contact us and the team that builds the platform will answer directly. Related: Privacy Policy, Data Processing Addendum, SLA.