Security First. Always.
We treat your infrastructure data with the same care we apply to our own. Here's how we keep it safe.
How we protect your data
Encryption at Rest & In Transit
Integration credentials are encrypted with AES-256-GCM. All transport is TLS 1.3. We never store plaintext credentials in the database.
Regular Security Audits
Annual SOC 2 Type II audit by a certified third-party firm, with independent penetration testing on a regular cadence.
Per-Tenant Data Scoping
Tenant ID rides on every JWT and applies as a row-level filter on every query. Multi-org users switch context cleanly; data never crosses boundaries.
Role-Based Access Control
Owner, admin and member roles with assignable permissions at the organisation level. Custom RBAC roles available on Enterprise.
Responsible Disclosure
We accept and triage every report through [email protected] with a PGP key for sensitive details. Researchers are credited.
Self-Hosted Deployment
Run the same four backend services in your own environment as Docker images — single compose file, profile-based modes. Full data residency in your hands.
SAML / OIDC SSO + SCIM 2.0
Per-org SAML 2.0 (crewjam/saml) or OIDC discovery — Okta, Azure AD, Google Workspace, OneLogin, JumpCloud. SCIM 2.0 provisioning on Enterprise. Plus TOTP MFA with org-wide enforce-MFA on Pro+.
Data ResidencyRoadmap
Choose your data region — US, EU, or APAC. Your data never leaves your selected region without your explicit consent.
Customer-managed keys (BYOK)Roadmap
Per-tenant encryption keys via your KMS (AWS KMS, GCP KMS, Azure Key Vault). Rotate and revoke on your schedule, end-to-end.
Certifications & Compliance
Our compliance posture covers the most rigorous standards in the industry. Download our security documentation or request our Data Processing Agreement (DPA).
Audit log details
Responsible Disclosure
Found a security vulnerability? We take all reports seriously and respond within 24 hours. We'll credit you in our Security Hall of Fame.