Encrypted in transit and at rest
TLS 1.3 on every connection, AES-256 on managed Postgres + object storage, customer-managed keys on request.
We use a few cookies to keep this site working, plus optional ones for analytics and live chat. Read our cookie policy.
Trust
Our compliance posture, the controls behind it, and where the data physically lives. We treat enterprise diligence as a first-class feature, not an afterthought.
Audited
Annual third-party audit covering security, availability, and confidentiality. Report available under NDA.
Audited
EU data protection agreement, processor terms, and cross-border transfer mechanisms in place.
In progress
Information security management system aligned to ISO 27001 controls. Certification audit in flight.
In progress
BAA-ready posture for healthcare workloads. Customer-side activation requires a signed agreement.
Audited
Stripe handles cardholder data end-to-end. We never touch a PAN; SAQ A scope only.
Audited
California consumer rights honoured globally — access, deletion, and opt-out flows wired into the dashboard.
TLS 1.3 on every connection, AES-256 on managed Postgres + object storage, customer-managed keys on request.
Row-level security on every table, role-scoped admin actions, hardware-backed SSO for staff with mandatory 2FA.
External penetration tests twice a year. Static analysis + dependency review on every PR.
EU, US, or APAC primary regions. Backups stay in-region with documented retention windows.
Read the security model or pull the latest status — every artefact links back here.