Skip to main content
Enterprise-Grade Security

Security First. Always.

We treat your infrastructure data with the same care we apply to our own. Here's how we keep it safe.

SOC 2 Type II
Annual audit
GDPR
Compliant
ISO 27001
Certified
HIPAA
Ready

How we protect your data

Encryption at Rest & In Transit

Integration credentials are encrypted with AES-256-GCM. All transport is TLS 1.3. We never store plaintext credentials in the database.

Regular Security Audits

Annual SOC 2 Type II audit by a certified third-party firm, with independent penetration testing on a regular cadence.

Per-Tenant Data Scoping

Tenant ID rides on every JWT and applies as a row-level filter on every query. Multi-org users switch context cleanly; data never crosses boundaries.

Role-Based Access Control

Owner, admin and member roles with assignable permissions at the organisation level. Custom RBAC roles available on Enterprise.

Responsible Disclosure

We accept and triage every report through [email protected] with a PGP key for sensitive details. Researchers are credited.

Self-Hosted Deployment

Run the same four backend services in your own environment as Docker images — single compose file, profile-based modes. Full data residency in your hands.

SAML / OIDC SSO + SCIM 2.0

Per-org SAML 2.0 (crewjam/saml) or OIDC discovery — Okta, Azure AD, Google Workspace, OneLogin, JumpCloud. SCIM 2.0 provisioning on Enterprise. Plus TOTP MFA with org-wide enforce-MFA on Pro+.

Data ResidencyRoadmap

Choose your data region — US, EU, or APAC. Your data never leaves your selected region without your explicit consent.

Customer-managed keys (BYOK)Roadmap

Per-tenant encryption keys via your KMS (AWS KMS, GCP KMS, Azure Key Vault). Rotate and revoke on your schedule, end-to-end.

Certifications & Compliance

Our compliance posture covers the most rigorous standards in the industry. Download our security documentation or request our Data Processing Agreement (DPA).

SOC 2 Type II Report
Available under NDA
Privacy Policy
Last updated Feb 2026
Data Processing Agreement
GDPR Article 28 compliant
Penetration Test Summary
Q4 2025 by Cobalt.io

Audit log details

23:59:01user.login[email protected]
23:57:44alert.create[email protected]
23:55:12monitor.updateapi-key-prod
23:51:03team.invite[email protected]

Responsible Disclosure

Found a security vulnerability? We take all reports seriously and respond within 24 hours. We'll credit you in our Security Hall of Fame.

Security FAQ