Compliance
What the platform does to protect your data, and where each framework actually stands. We list status, not badges.
Practices
Encryption
Secrets are encrypted at rest with AES-256-GCM envelope encryption. Customer data is encrypted in transit with TLS 1.2 or later.
Tenant isolation
Every query runs under row-level security scoped to the workspace. Cross-tenant reads are blocked at the database, not only in application code.
Audit trail
Who did what, when, and from where is recorded for every privileged action and retained for seven years in write-once storage.
Data deletion
Deletion requests are honoured within 30 days. Right-to-be-forgotten is implemented and tested, not a manual process.
Incident notification
Customers are notified of security incidents affecting their data within 72 hours.
Availability
The uptime objective is 99.9% per service, measured continuously. Enterprise plans carry a written SLA.
Frameworks
| Framework | Status | Detail |
|---|---|---|
| SOC 2 | Controls mapped | Control mapping complete; attestation not yet performed. |
| GDPR | Aligned | DPA available; subprocessor list maintained; DSAR tooling in the product. |
| HIPAA | Controls mapped | BAA considered as part of an enterprise security review. |
| ISO 27001 | Not certified | No certification held. |
| FedRAMP | Aligned | Control mappings to NIST 800-53; no authorisation held. |
Need evidence for a security review? Contact us and the team that builds the platform will answer directly. Related: Privacy Policy, Data Processing Addendum, SLA.