Encryption everywhere
TLS 1.3 everywhere; AES-256 at rest. Secrets handled via a vault — never logged, never on disk in plaintext.
We use a few cookies to keep this site working, plus optional ones for analytics and live chat. Read our cookie policy.
Security
A short read of the controls behind every feature — encryption, access, monitoring, and how to reach our security team.
TLS 1.3 everywhere; AES-256 at rest. Secrets handled via a vault — never logged, never on disk in plaintext.
OAuth + email + 2FA for tenants; SSO + WebAuthn for staff. Database access is row-level with audited changes.
Sentry alerts, anomaly detection on auth events, and a 24/7 on-call rotation. Mean time to acknowledge: <10 minutes.
A documented vulnerability disclosure programme, a public PGP key, and a 72-hour acknowledgement SLA.
We honour responsible disclosure and credit researchers who help us harden the platform. Email us with a reproducible report and we will respond within 72 hours.
Audit reports, compliance attestations, and the live operational status are all one click away.