01 · Trust Center · Security FAQ
Answers to common questions about how we protect your data and ensure confidentiality — written for IT, legal, and risk stakeholders.
02 · Security review status
We distinguish between a control that is implemented in the platform and a control that has been independently verified by a third party. Independent security assessment: Planned. A technical security review is recommended before enterprise launch, and no penetration testing or certification has been performed to date.
| Area | Control | Status |
|---|---|---|
| Data protection | Encryption in transit (TLS) | Implemented |
| Data protection | Encryption at rest by the managed database provider | Implemented |
| Access control | Row-level security on application tables | Implemented |
| Access control | Server-side role checks for administrative access | Implemented |
| Access control | Organization-level data isolation | Implemented |
| Authentication | Email/password authentication with password reset | Implemented |
| Authentication | Multi-factor authentication for customer accounts | Implemented |
| Application security | Server-side scoring so results cannot be altered by a client | Implemented |
| Application security | Secrets held in managed server-side configuration | Implemented |
| Monitoring & logging | Audit logging on sensitive operations | Implemented |
| Monitoring & logging | Alerting and formal log review process | Planned |
| Infrastructure | Managed cloud infrastructure with provider-maintained controls | Independent verification required |
| Backup & recovery | Managed database backups | Independent verification required |
| Backup & recovery | Documented and tested recovery procedure | Planned |
| Operations | Rate limiting on public endpoints | Implemented |
| Assurance | Independent security assessment / penetration test | Planned |
16 of 16 questions
Document version: 0.9 · Last reviewed: 2026-08-17 · Status: Reviewed