Security
How we protect your data.
Last updated 2026-06-07.
At rest
Postgres on Fly.io (US region). Disk-level encryption. Backups encrypted, taken nightly with a 7-day rolling retention.
In transit
TLS 1.2+ everywhere. HSTS on the edge. Internal service calls go over Fly’s private network.
Authentication
Magic-link only. No passwords to phish. Sessions live as HMAC-signed HttpOnly cookies, 30-day expiry, rotated on every sign-in. Magic-link tokens are SHA-256 hashed in the DB; the raw token never leaves the email.
Tenant isolation
Every business table carries a tenant_id scoped at the query layer. Postgres row-level security policies are on the roadmap and will land before the public paid launch.
AI traffic
Calls route to Anthropic’s API. Per Anthropic’s policy, prompts and outputs are not used to train their models. We log only what’s needed for billing and error attribution — never raw prompt bodies unless an error’s being diagnosed.
What we don’t have yet
- SOC 2 report. We’re in scope for V1; happy to share progress detail under NDA.
- SSO / SAML. Roadmapped; not in V0.
- Customer-managed keys. Available on enterprise conversations; not in V0.
Reporting a vulnerability
Email [email protected]. Acknowledged within 24 hours, triaged within 72. We don’t pay a bounty in V0 but we’ll credit you publicly when the fix ships unless you’d rather we didn’t.