Your data is your business
We treat the security of your business data the way we'd treat our own. Encryption, access control, audit trails, and honest defaults — everywhere.
Encryption at rest and in transit
All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Secrets — including OAuth tokens and MFA secrets — are stored under master-key encryption, never in plaintext.
Role-based access control
Granular roles and permissions decide who can view, edit, and export what. Sensitive operations like data export are permission-gated and audited.
Two-factor authentication
Authenticator-based MFA with recovery codes, plus sign-in rate limiting that throttles both per-IP and per-account brute force attempts.
Complete audit trails
Every login, failed login, permission change, export, and MFA event is logged with actor, timestamp, and request metadata — reviewable from the security center.
How we handle sensitive data
- Least privilege. AI features only see the data they need for the task you requested.
- No plaintext secrets. API keys, OAuth tokens, and MFA secrets are encrypted at rest with a master key.
- Honest AI. Responses include evidence, confidence, and assumptions — nothing is executed without your approval.
- Secure by default. HTTP-only cookies, SameSite=Lax, and HTTPS in production.
Need a security review, DPA, or SSO for your team? Contact our security team.
See the security controls yourself
Start free and explore the security center in your workspace.