Skip to content

Serious security. Simply explained.

Enterprise-grade controls, clear defaults, and documentation when you need it.

Access

  • SSO — OIDC and SAML
  • Roles — Admin, Editor, Viewer
  • Invites — Add team members. Revoke immediately

Data

  • Encryption — In transit and at rest. Field-level for sensitive data
  • Hosting — Google Cloud Platform. US-Central1 default. Other regions on Enterprise
  • Secrets — GCP Secret Manager. Nothing in code
  • PII — Log redaction. Data classification

Compliance

  • GDPR-aligned — Deletion on request. Configurable retention
  • Residency — Control where data lives
  • Audit logs — Exportable. Who did what, when

Infrastructure

  • Uptime — 99.9% target. Auto-scaling. Failover
  • Threat model — Documented. Prompt injection, XSS, SSRF, exfiltration. Reviewed regularly
  • Crawler — Domain allowlists. Rate limiting. Egress controls
  • Embed — CSP. SRI. Origin validation

Questions about security?

We’re happy to discuss our security posture in detail. Contact us for documentation or to schedule a review.

Contact us