We take your security obsessively seriously
This page documents how we protect your data, our security practices, and how to report any vulnerabilities you discover.
ISO 27001 practices
We follow ISO 27001-aligned controls (not yet certified)
TLS 1.3 encryption
All data in transit and at rest
Code review & dependency scanning
Code review and dependency scanning built into our process
NDAs by default
Mutual NDA signed before any discussion
Found a vulnerability?
We welcome responsible disclosure of vulnerabilities in our products. Send your report to:
PGP key available on request.
We take every report seriously and offer public credit to researchers who disclose responsibly.
How we protect your data
Data minimization
We collect only what we need. We never store client credentials.
Secrets management
All secrets are kept in a managed secrets store with encrypted environment variables.
Regular backups
Regular encrypted database snapshots with off-site storage.
Code review
No code reaches main without review and automated checks.
Deletion after delivery
We delete all personal data and credentials 90 days after final delivery.