Security & trust

We sell security.
Of course we use it on ourselves.

Every customer asks: "How do you protect MY data?" Here's the full picture — controls, sub-processors, residency, and how to report a vulnerability.

Six pillars of our posture

AES-256-GCM at rest

Every customer credential we store (Cloudflare tokens, GitHub OAuth, Slack webhook URLs) is encrypted with AES-256-GCM via a versioned `ENCRYPTION_KEY`. Database backups inherit the same encryption.

TLS 1.3 in transit

All API endpoints enforce TLS 1.3; SSL Labs A+ rating with HSTS preload. We probe our own outbound TLS posture daily and alert if the score regresses.

Hardware-backed MFA

Owner accounts must enrol TOTP MFA within 2 days of signup; aal2 enforcement across the dashboard. WebAuthn/Passkeys land Q3.

SOC 2 aligned controls

We run 20 of the SOC 2 Trust Services Criteria controls continuously against our own platform. Evidence collection is automated.

Continuous self-monitoring

Our own scanner runs against our own domains. We eat our own dog food — every check we sell, we run on ourselves daily.

Our live score badge is activating — check back soon for the real-time number.

Regional residency — on the roadmap

Per-tenant data-residency pinning (EU / US / APAC) is architected in our schema and codebase, but not yet live — every organisation is stored in the same single-region Supabase project today. See the Trust Centre for current status.

Sub-processors

Every third-party service in our data path — 21 today, updated whenever we add or remove a vendor. The canonical list with DPAs lives on the sub-processors page (SOC 2 control CC9.1).

Sub-processorPurposeRegion
SupabasePostgres + auth + object storageSingle region
CloudflareEdge/CDN + DDoS in front of our app; WAF automation for customer domainsGlobal
StripeSubscription billing + tax + checkoutUS/EU
BrevoTransactional email deliveryEU
Kapso.aiWhatsApp Business message routingUS
WorkOSEnterprise SSO (SAML/OIDC) + SCIM provisioningUS
OpenAILLM — primary (triage, plain-language rewrite, chat)US
AnthropicLLM — fallback providerUS
OpenRouterLLM router — catch-all fallbackUS
MiniMaxLLM — APAC-region fallbackAPAC
HIBPBreach + credential-leak dataUS
Google Safe BrowsingURL reputation classificationUS
VirusTotalURL + file reputation enrichmentUS
MXToolboxEmail blacklist lookupUS
URLScan.ioPhishing-page sandbox + screenshotEU
OSV.devOpen-source vulnerability databaseUS
NVDNational Vulnerability Database (CVSS metadata)US
EPSSExploit Prediction Scoring SystemUS
GitHubGitHub App — repo scanning (installing customers only)US
SentryError tracking + performance monitoringUS
NamecheapDomain availability lookup (brand protection)US

Aligned with industry standards

SOC 2 AlignedGDPR ReadyISO 27001 PrinciplesTLS 1.3OWASP Top 10PCI-DSS Aware