In plain words
What we do to protect you, explained without jargon.
Your conversations are private
Everything sent and received is encrypted in transit, like a sealed envelope. Not even we can read it along the way.
Your data stays separate
Your business data lives in its own isolated space. It never mixes with another company's data, even on shared infrastructure.
Only the right people get in
Your admins need two steps to log in — like having a key and a code. And each person only sees what they need for their role.
We tell you if something happens
If we detect a security issue that affects you, we notify you within 72 hours. It's the law, and it's the right thing to do.
Your data is always recoverable
We keep automatic backups for 30 days. If something goes wrong, we can restore your data to exactly how it was at any point in time.
Your data belongs to you
You can export, correct, or delete all your information at any time. No fine print, no lock-in.
Compliance
At a glance
Controls
All controls implemented and tracked.
Infrastructure security
- TLS 1.2+ encryption in transit
- AES-256 encryption at rest
- Per-tenant isolation (PostgreSQL schemas)
- Continuous PITR — 30-day window (Neon)
Access control
- Mandatory MFA for admins
- Role-based access control (RBAC)
- Quarterly access reviews
- Employee offboarding < 24h
Monitoring & audit
- PII access logs — 365-day retention
- Privileged admin action audit trail
- Incident response SLA P1 < 4h
- Breach notification ≤ 72h (GDPR Art. 33)
Development security
- Dependabot — weekly dependency scanning
- npm audit blocks high/critical CVEs in CI
- Semgrep SAST on every Pull Request
- Branch protection — PR required for main
Privacy & legal
- DSAR endpoints — data export and erasure
- Records of Processing Activities (RoPA)
- Data Processing Agreement (DPA)
- 30-day notice before subprocessor changes
Security policies
- 17 policies documented and versioned in git
- Business continuity & DR plan
- Responsible disclosure policy
- Risk register — tracked in database
Subprocessors
Third parties that process personal data on our behalf. We give 30 days notice before adding or replacing a subprocessor.