Growth
Accent color

Applied instantly across the site.

Sign in Start free
Security

Your data is your business

We treat the security of your business data the way we'd treat our own. Encryption, access control, audit trails, and honest defaults — everywhere.

AES-256Encryption at rest
TLS 1.2+Encryption in transit
2FATwo-factor by default
100%Audit logging of sensitive actions

Encryption at rest and in transit

All data is encrypted at rest (AES-256) and in transit (TLS 1.2+). Secrets — including OAuth tokens and MFA secrets — are stored under master-key encryption, never in plaintext.

Role-based access control

Granular roles and permissions decide who can view, edit, and export what. Sensitive operations like data export are permission-gated and audited.

Two-factor authentication

Authenticator-based MFA with recovery codes, plus sign-in rate limiting that throttles both per-IP and per-account brute force attempts.

Complete audit trails

Every login, failed login, permission change, export, and MFA event is logged with actor, timestamp, and request metadata — reviewable from the security center.

How we handle sensitive data

  • Least privilege. AI features only see the data they need for the task you requested.
  • No plaintext secrets. API keys, OAuth tokens, and MFA secrets are encrypted at rest with a master key.
  • Honest AI. Responses include evidence, confidence, and assumptions — nothing is executed without your approval.
  • Secure by default. HTTP-only cookies, SameSite=Lax, and HTTPS in production.

Need a security review, DPA, or SSO for your team? Contact our security team.

See the security controls yourself

Start free and explore the security center in your workspace.

Start free