Security and deployment

Security claims you can check

See what is in place, where deployment choices change the boundary, and what we do not claim.

In place today

The controls below are current product and engineering behavior, not certification language.

Identity on open standards

Authentication and enterprise identity use protocols a reviewer already knows.

  • Authorization Code with PKCE, signed access tokens and published verification keys
  • Multi-factor authentication, enterprise single sign-on and directory synchronization
  • Roles, attribute conditions and organization- or application-scoped access

Isolation at the data layer

Tenant business data does not rely on one tenant column in a shared table.

  • A dedicated database role and credentials for each tenant data instance
  • Organization-scoped access across shared account services
  • Namespaced cache keys, event streams and file-storage paths

Evidence that detects alteration

Sensitive actions enter an append-only audit history whose chain can be verified.

  • Each audit event is hash-chained to its predecessor
  • Filter and export evidence, or inspect the history of one record
  • Alerts can fire on events such as failed sign-in or permission changes

Checks on every change

Security rules are enforced in the engineering workflow rather than left to memory.

  • Static application and dependency security analysis
  • Automated secret scanning before a change is accepted
  • Shared framework rules for authentication, data access and safe failure behavior

Deployment changes the boundary

The self-serve and dedicated paths do not make the same isolation or key-management promise.

Deployment path

Shared infrastructure

The self-serve path starts on shared infrastructure. Tenant access remains scoped, but a customer-managed encryption key is not offered on this tier.

Deployment path

Dedicated infrastructure

A customer-managed cloud key covering the dedicated database, its credential secret and organization file storage is planned, not yet available. The design keeps the key in the customer account with a revocable grant.

Maturity boundary

What we do not claim

  • There is no SOC 2 or ISO 27001 attestation today.
  • There is no completed independent penetration test today.
  • Customer-managed encryption keys (bring your own KMS) are planned, not available today. When shipped, they would not extend to cache or event-stream storage.
  • A roadmap item is not presented as a shipped control.

How a security review works

Start with the public facts, then add detail in proportion to the decision.

  1. Start with the public boundary

    Use this page to decide whether the current controls and stated gaps fit your evaluation.

  2. Bring the real checklist

    Use a technical walkthrough for your data flow, identity requirements and deployment constraints.

  3. Go deeper under NDA

    A detailed readiness assessment and pre-answered security questionnaire are available for qualified reviews.

Bring the checklist you actually use

We will separate what is shipped, what depends on deployment, and what remains open.