Trust Center

Everything a security reviewer needs, in one place.

The controls behind the platform, the frameworks we map to, who we work with, and how to reach us. No marketing fog.

Data protection

Encryption, end to end.

In transit

TLS 1.2+ on every connection, with HSTS (including subdomains) and upgrade-insecure-requests once a deployment is served over HTTPS. Session cookies are HttpOnly, SameSite and Secure under TLS.

At rest

Integration credentials, provider keys and webhook tokens are sealed with authenticated encryption (AES-128-CBC with HMAC-SHA256) before they touch the database. Tampered ciphertext fails closed rather than returning garbage.

Credentials

Passwords are stored only as salted, memory-hard hashes. A 12-character complexity policy, common-password screening and breach-style checks apply at sign-up and rotation.

Application security

Hardened on every request.

  • Content-Security-Policy with a per-request nonce, object-src 'none' and frame-ancestors 'none'
  • Clickjacking, MIME-sniffing and referrer-leak protection on every response
  • CSRF tokens on every state-changing form and API call, including sign-in
  • Session rotation on login and sign-out-everywhere via a per-user session epoch
  • Per-IP rate limiting and account lockout after repeated failures
  • Strict open-redirect protection on post-login navigation
  • Parameterised SQL throughout; no string-built queries reach the database
  • Organisation-scoped queries on every tenant-owned record
  • Server-side input validation and output escaping
  • Least-privilege roles and attributed administrative actions
  • No secrets in source — configuration comes from the environment
  • Cache-Control: no-store on authenticated console pages
Compliance

Frameworks we build against.

GDPR / UK GDPR

We act as processor for workspace data, offer a full Data Processing Addendum with SCCs for transfers, and honour data-subject rights including access, portability and erasure.

CCPA / CPRA

We do not sell personal information. California residents can exercise rights to know, delete, correct and opt out of sharing directly from the console or by contacting us.

SOC 2 (Type II in progress)

Controls are designed and monitored against the SOC 2 Trust Services Criteria. Our latest report and security questionnaire responses are available under NDA.

ISO/IEC 27001

Our ISMS follows ISO 27001 as the organising framework, with documented policies, risk treatment and continuous improvement.

PCI-DSS

We do not store card data. Payments, where taken, are handled entirely by a PCI-DSS certified processor.

Accessibility — WCAG 2.2 AA

We design to WCAG 2.2 Level AA. Read our accessibility statement or report a barrier any time.

Operational resilience

We plan for the bad day.

Incident response

A written IR plan with defined severities and owners. We notify affected customers without undue delay after confirming a personal-data breach.

Logging & monitoring

Authentication events, administrative actions and data exports are attributed and logged. Anomalies — repeated failures, lockouts, mass exports — surface in the Security center.

Backups & recovery

Encrypted, monitored backups with a documented recovery objective. Backups cycle out within 35 days and are tested as part of the IR programme.

Vulnerability management

Dependency and container scanning, continuous review against published advisories (CVE/NVD), and prompt patching based on severity.

Change control

Reviewed changes, environment separation and reproducible deployments. Database migration is idempotent and non-destructive.

Data portability

Export any view as CSV, or download a fully encrypted copy of your whole workspace from the Security center at any time.

Need our security package?

We'll send our questionnaire responses and reports.

Tell us what your reviewer needs — SIG, CAIQ, DPIA or a live walkthrough — and we'll turn it around quickly under NDA.