Security Policy

Effective 9 August 2026

Your business plan, client data and internal documents are the most sensitive things you will put in this platform. This page explains the controls that protect them and how to reach us if you find a weakness.

Access control

Every workspace record is protected by row-level security in the database, so a request can only ever read the rows the signed-in account is entitled to. Roles are stored separately from profiles and checked server-side, which means permissions cannot be escalated from the browser. Sensitive actions — governance edits, document deletion, clerical approvals and administrative screens — require an explicit role.

Authentication

Sign-in supports email, Google and Apple, with optional time-based multi-factor authentication. Sign-in attempts, method, and device metadata are written to a security audit log you can review in account settings.

Encryption and infrastructure

Traffic is encrypted in transit with TLS, and data at rest is encrypted by our managed cloud provider. Secrets are held in a managed store and are never shipped to the browser. Backups are taken on a rolling schedule.

Continuous scanning and the regression gate

Automated security scans run on a schedule and publish their verdict to an internal gate. Every closed finding is registered with machine-checkable guards, and our continuous integration pipeline re-verifies each one on every change — a reintroduced weakness blocks the deployment instead of reaching production. Open critical or high findings fail the gate outright.

Incident response

Suspected incidents are triaged immediately, contained, and recorded with a timeline. Where a confirmed breach affects your personal data, we notify affected customers and the relevant regulator without undue delay and, where legally required, within 72 hours of becoming aware.

Reporting a vulnerability

We welcome good-faith research. Report findings through the contact options on our homepage with enough detail to reproduce the issue. Please do not access other customers’ data, degrade the service, or run automated scans against production. We will acknowledge your report, keep you updated, and will not pursue legal action against researchers who follow this policy.

Your part

Use a unique password, turn on multi-factor authentication, review your login history, remove collaborators who no longer need access, and keep connected channel credentials current.

Other policies