SOC 2
Type II certified
GDPR
DPA and data subject rights
TLS 1.2+
Encryption in transit and at rest
Trust Center
Policies, reports, and FAQs
Program overview
Our security program is aligned to SOC 2 and GDPR, and we continuously improve our controls as we scale.
Security training and background checks for employees.
Least-privilege access and role-based authorization.
Peer review and change management for production changes.
Continuous vulnerability management and regular dependency updates.
Business continuity and incident response procedures.
Data protection
TLS 1.2+ in transit, modern ciphers at rest.
Segregated production environment and secure secrets management.
Retention policies and regular restore testing.
Monitoring and audit logs on critical systems.
Data minimization by default and customer data deletion upon request.