Security & Trust
What we do, described plainly. We hold no certifications and this page claims none.
We would rather describe our practices accurately than display a badge. If a certification is a procurement requirement for you, tell us early — we will say whether we hold it, and the answer today is that we do not.
Access to customer data
Staff access to customer data is off by default. Access is granted for a specific request, for a bounded period, and is recorded. Customers can request the access record for their tenancy.
Support work is done against the customer's own view of the data wherever possible, so that answering a question does not require broader access than the question needs.
Tenancy
Each customer's records are logically separated, and every query is scoped to a tenancy at the data layer rather than in application code. Separation enforced only by application logic fails the moment application logic has a bug, which is the wrong place to put the guarantee.
Encryption
Data is encrypted in transit using current TLS, and at rest using platform-managed keys. Backups carry the same protection as primary storage.
We do not currently support customer-managed keys. It is a reasonable thing to want and we would rather say so than describe our arrangement in language that implies more control than you have.
Authentication
Password authentication with a second factor, or SSO through your identity provider using SAML or OIDC. Where SSO is enabled, we recommend disabling password authentication entirely so that account lifecycle stays with your directory. Sessions expire on inactivity and can be revoked centrally by a tenancy administrator.
Backups and recovery
Records are backed up on a rolling schedule with a defined retention window, and restores are tested periodically rather than assumed. Given what this product is for, it would be poor form to keep continuity documentation for other people without exercising our own.
Sub-processors
We use a small number of sub-processors for hosting, email delivery and error reporting. The current list, and the data each one touches, is available on request and before contract. We give notice before adding one.
Vulnerability disclosure
If you believe you have found a vulnerability, contact us and we will acknowledge within two business days. We will not pursue action against anyone who reports in good faith, avoids accessing data that is not theirs, and gives us reasonable time to fix the issue before publishing.
We do not run a paid bounty programme.
What we do not claim
- We hold no ISO, SOC, PCI or equivalent certification, and no audit has been performed against our controls.
- We are not accredited by any standards body.
- We hold no vendor partner tier or competency designation.
A security page is worth reading only if the absences are stated as clearly as the presences. These are ours.