We protect every tenant with encryption at rest and in transit, EU-only hosting, role-based access control and a formal vulnerability disclosure programme.
Detailed documentation of our security controls, practices and policies for enterprise prospects and compliance teams.
Encryption algorithms, backup schedules, access control, audit logging and our vulnerability management cycle.
Read more →How to report a vulnerability, our 90-day coordinated disclosure policy and our hall of fame for recognised researchers.
Read more →Data categories, sub-processors, legal basis for processing, retention schedules and data-subject rights under the GDPR/AVG.
Read more →Every tenant runs on its own isolated database with separate credentials. Cross-tenant data access is architecturally impossible.
Read more →TOTP-based 2FA is mandatory for the owner role. All team members can be required to enrol via the settings panel.
Read more →Scale and Sovereign tenants can bring their own database hosted on their own infrastructure. We store only connection metadata.
Read more →Our security team is available to answer compliance questionnaires and enterprise due-diligence requests.
Contact security team →