Trust & Security
How we protect your data, the controls behind our platform, and exactly where we stand on the path to formal certification.
Where we stand
We're transparent about our posture — including what's still in progress. Live status is always current on our trust center.
SOC 2
Implementing and documenting the security, availability, and confidentiality controls required for a SOC 2 examination.
GDPR
EU data-subject rights are honored — access, rectification, erasure, and portability — with lawful processing and clear consent.
CCPA / CPRA
California residents can access and delete their personal information and opt out of its sale or sharing.
Status reflects our internal readiness, not a completed third-party audit. Our SOC 2 examination is in progress; we do not claim to be certified.
How we protect your data
Security is built into how we design, ship, and operate every system — not bolted on afterward.
Infrastructure & hosting
Workloads run on a GitOps-managed Kubernetes platform with network segmentation, infrastructure defined as code, and least-privilege workload identities in place of long-lived credentials.
Application security
Authentication is built on OAuth 2.0 with server-side session invalidation and CSRF protection. Secrets are encrypted, and dependencies are continuously scanned for known vulnerabilities.
Data protection
Data is encrypted in transit with TLS and at rest, with additional field-level encryption for sensitive values. Object storage is provider-agnostic and access-scoped per bucket.
Access control
Access follows the principle of least privilege with role-based permissions, and sign-in supports passwordless and multi-factor authentication for administrative accounts.
Monitoring & response
Errors and performance are monitored centrally, sensitive actions are audit-logged, and policy-as-code admission controls enforce guardrails across the cluster.
Vendors & subprocessors
We rely on a vetted set of subprocessors for infrastructure, payments, and communications. The full, current list is maintained in our trust center.
See the full details
Our live trust center hosts the complete control catalog, policies, and subprocessor list — and lets you request documentation under NDA.
