Encryption everywhere
TLS 1.2+ for all traffic in transit, AES-256 encryption at rest, and passwords stored with a modern memory-hard hash.
You trust us to watch your infrastructure — here is how we protect ours, and your data with it.
TLS 1.2+ for all traffic in transit, AES-256 encryption at rest, and passwords stored with a modern memory-hard hash.
Two-factor authentication for every account, SSO/SAML on Business plans, and scoped API keys you can rotate at any time.
Monitoring probes run in isolated networks with no access to customer data stores. Production access requires hardware-key MFA.
We align our controls with SOC 2 and are working with an independent auditor toward formal certification. Our GDPR data-processing agreement and current subprocessor list are available on request.
Found a vulnerability? We want to hear about it. Email [email protected] with details and steps to reproduce. We acknowledge reports within 48 hours, keep you informed while we fix the issue, and credit researchers who report in good faith. Please avoid accessing other customers' data or degrading the service while testing.
Security questionnaires and audits for Business and Enterprise customers: contact us and pick "Sales & Enterprise".