01 · Trust Center · Security FAQ

Security & Data Protection FAQ

Answers to common questions about how we protect your data and ensure confidentiality — written for IT, legal, and risk stakeholders.

Confidential by DesignEncrypted in Transit & at RestLeast-Privilege AccessBuilt with Enterprise Requirements in Mind

02 · Security review status

Implemented controls, stated plainly.

We distinguish between a control that is implemented in the platform and a control that has been independently verified by a third party. Independent security assessment: Planned. A technical security review is recommended before enterprise launch, and no penetration testing or certification has been performed to date.

Security control implementation status
AreaControlStatus
Data protectionEncryption in transit (TLS)Implemented
Data protectionEncryption at rest by the managed database providerImplemented
Access controlRow-level security on application tablesImplemented
Access controlServer-side role checks for administrative accessImplemented
Access controlOrganization-level data isolationImplemented
AuthenticationEmail/password authentication with password resetImplemented
AuthenticationMulti-factor authentication for customer accountsImplemented
Application securityServer-side scoring so results cannot be altered by a clientImplemented
Application securitySecrets held in managed server-side configurationImplemented
Monitoring & loggingAudit logging on sensitive operationsImplemented
Monitoring & loggingAlerting and formal log review processPlanned
InfrastructureManaged cloud infrastructure with provider-maintained controlsIndependent verification required
Backup & recoveryManaged database backupsIndependent verification required
Backup & recoveryDocumented and tested recovery procedurePlanned
OperationsRate limiting on public endpointsImplemented
AssuranceIndependent security assessment / penetration testPlanned

16 of 16 questions

Document version: 0.9 · Last reviewed: 2026-08-17 · Status: Reviewed