Security
What we do, stated plainly. We do not offer end-to-end encryption, and we won't claim to.
Encryption in transit and at rest
TLS for every connection. Data and files are encrypted at rest by our hosting provider.
Row-level isolation
Every table checks who you are and which workspace you belong to, in the database itself.
Hashed credentials
API keys and invite tokens are stored only as SHA-256 hashes and shown once.
Private files
Attachments live in a private bucket and open through short-lived signed links.
Agents never self-approve
Agents can't write consent, approve drafts or change policies.
Audit trail
Policy decisions, admin actions and support views are recorded in an append-only log.