Security

Your data stays exactly where it should.

Audited infrastructure, structured controls, and a public track record. This isn't a page of marketing adjectives — it's the real map.

All systems operational
Uptime 99.993% · 12-mo trailing
0 active incidents
Last incident: 347 days ago
Status page
Control matrix

What we've implemented, per domain.

Domain
Control in place
Standard
Status
Encryption

TLS 1.3 in transit; AES-256 at rest

SOC 2 CC6.1
Live
Authentication

bcrypt hashing; SSO, TOTP 2FA, WebAuthn

SOC 2 CC6.6
Live
Infrastructure

AWS + Cloudflare; automatic patching; segmented VPCs

SOC 2 CC7.2
Live
Access control

Row-level security; least-privilege IAM; just-in-time prod access

SOC 2 CC6.3
Live
Backups

Point-in-time restore; 30-day retention; quarterly DR drills

SOC 2 A1.2
Live
Data handling

No sale, no ML training on individual data, no ad sharing

GDPR Art. 5
Live
Audit history

Every audit, every finding, public.

Incidents and findings are published with dates, auditor names, and remediation status. Nothing hidden.

Jan 2026

SOC 2 Type II renewal

Performed by Prescient Security, LLC

No material exceptions. Report available under NDA.

Pass
Nov 2025

Penetration test (external)

Performed by Trail of Bits

3 low-severity findings, all remediated within 48h. Report available to enterprise customers.

Pass
Aug 2025

Dependency audit

Performed by Internal (Socket.dev + manual)

2 deprecated packages replaced. Zero known CVEs in production tree as of audit date.

Pass
Feb 2025

Pen-test (internal architecture)

Performed by Cure53

1 medium finding (header leak), patched in 24h. Full report published.

Pass
Bug bounty

Hall of Fame

Total paid out in the last 12 months: $9,700 across 4 researchers. Payouts range $200 → $10,000 depending on severity.

Report a vulnerability
JD
j.darsano
Auth bypass in SSO edge case
$4,200
KH
kate.h
IDOR in shared playbook link
$2,800
RM
rmz
XSS in broker-import error path
$1,500
TL
t_l1u
Rate-limit bypass on public API
$1,200

Enterprise security docs?

SOC 2 report, pen-test summary, DPA, and custom contracts available for teams on Scale and Enterprise plans.