Security architecture
See the public Trust Center for facts about hosting, subprocessors and controls. Under NDA we share the threat model, security controls matrix, penetration test scope, incident response runbook, DR plan and the security questionnaire pack.
Key properties: Postgres RLS on every tenant table; permissions re-checked server-side; append-only hash-chained audit log; signed CRA snapshots; AES-256-GCM for integration secrets; SSRF guards; rate limiting; hardened SBOM parsing; feature flags for staged rollouts; no code execution.
Last updated . This page describes the current release.