What’s in place
Your data is encrypted, access is scoped to each account, and sensitive actions are logged.
Connections run over TLS, and your data is stored encrypted with AES-256, so it's protected on the wire and on disk.
Each account only ever touches its own records. The rules are enforced at the database, not just in the app.
Sign in with email verification or magic links. Multi-factor authentication is on the roadmap.
Sensitive actions get written to an audit trail, so there's a record of who did what and when.
The details
The longer version, for anyone who wants to know exactly how it works.
If something goes wrong
If a security incident happens, we follow a set process: we tell the users who are affected, isolate the problem, and work to restore data. No spin, no burying it.
On the roadmap
We’d rather show you the honest list than pretend everything’s already done.
A second step at sign-in for accounts that want it.
Working toward a formal audit. Not certified yet.
Finer control over who can do what inside a workspace.
We're happy to walk through how your data is stored and protected. Ask us anything.