Certifications
SOC 2 Type II (annual). ISO 27001 in progress (target: 2026 Q3). GDPR-compliant DPA available on request.
Our security posture, the certifications we hold, and the engineering practices that back them. The full SOC 2 report is available under NDA.
SOC 2 Type II (annual). ISO 27001 in progress (target: 2026 Q3). GDPR-compliant DPA available on request.
AES-256 at rest. TLS 1.2+ in transit. Customer-managed encryption keys on Custom plans (BYOK via AWS KMS).
SSO/SAML on Pro and Custom plans. SCIM provisioning on Custom. Role-based access with granular permissions. Audit logs for every privileged action — immutable, exportable.
Continuous dependency scanning (Dependabot, Snyk). Quarterly third-party penetration tests. 24-hour patch SLA for critical CVEs.
On-call rotation, 99.95% target. Incident timeline published within 5 business days at /legal/security/incidents. Customers notified within 24 hours of any incident affecting their data.