Security Policy
Last updated: 24 July 2026
This Security Policy summarizes the measures we take to protect the Service and Customer Data. It is a summary, not a warranty; see the Terms of Service.
Data protection
Data is encrypted in transit (TLS) and at rest. Passwords are stored using strong one-way hashing; we never see them.
Access control
Access within a workspace is governed by roles and permissions. Material actions are recorded on an append-only audit trail with actor, timestamp, and before/after values.
Tenant isolation
Each customer workspace is logically isolated; access requires an active membership resolved on every request. Database-level isolation hardening is on our roadmap.
AI safety
AI features use permission-bounded retrieval, treat project records as untrusted data (guarding against prompt injection), refuse out-of-scope requests, and are rate-limited. AI cannot take actions or approve anything — humans do.
Operations
We use reputable cloud infrastructure with managed backups and apply security updates promptly.
Reporting
Report security concerns to [email protected] and see the Responsible Disclosure Policy.
Questions about this document? Contact [email protected]. See all policies in the Legal Center.