Security

How we handle your data

Your business data runs your operations. Here's what we have in place to protect it, and what we're still building.

What’s in place

The basics, done right.

Your data is encrypted, access is scoped to each account, and sensitive actions are logged.

01

Encryption in transit and at rest

Connections run over TLS, and your data is stored encrypted with AES-256, so it's protected on the wire and on disk.

02

Access stays scoped

Each account only ever touches its own records. The rules are enforced at the database, not just in the app.

03

Sign-in options

Sign in with email verification or magic links. Multi-factor authentication is on the roadmap.

04

Activity logging

Sensitive actions get written to an audit trail, so there's a record of who did what and when.

The details

How your data is protected.

The longer version, for anyone who wants to know exactly how it works.

If something goes wrong

You’ll hear it from us.

If a security incident happens, we follow a set process: we tell the users who are affected, isolate the problem, and work to restore data. No spin, no burying it.

On the roadmap

What we’re building next.

We’d rather show you the honest list than pretend everything’s already done.

01

Multi-factor authentication

A second step at sign-in for accounts that want it.

02

SOC 2 exploration

Working toward a formal audit. Not certified yet.

03

Advanced user permissions

Finer control over who can do what inside a workspace.

Questions about any of this?

We're happy to walk through how your data is stored and protected. Ask us anything.