Enterprise-grade security and compliance
Every message runs a gauntlet of controls — authenticated, encrypted, authorized and audited — before it reaches your customers. Security your legal team can sign off on.
Compliant by design
Independently audited against the standards enterprise buyers and their legal teams already require — so security review is a formality, not a blocker.
Reports and certificates are available under NDA — renewed and re-audited every year.
Security in depth
Protection layered from the wire to the database to the API — each control working independently so no single failure exposes your customers.
Data protection
- Encryption in transitTLS 1.2+ on every connection
- Encryption at restAES-256 across all stored data
- Data residency optionsPin storage to the EU, US and more
- Automated backupsPoint-in-time recovery, tested regularly
Access & governance
- Role-based access controlScope every team member precisely
- SSO / SAMLOkta, Azure AD, Google and more
- Full audit logsEvery action, timestamped and exportable
- Least-privilege API scopesToken-level limits on what code can touch
You decide who can do what
Map every person to a role and every role to an exact set of permissions. Least privilege by default — nobody touches what they don't need.
Security your team can trust
Talk to us about enterprise controls, data residency, a DPA and your security review — we'll meet you where you are.
Security & compliance — frequently asked questions
You do. Your data is yours — you can export it at any time, and you can request permanent deletion of your account data, which we complete within the timeframes set out in our contract and privacy commitments.
You choose your data residency region — EU, US and more. Data stays in the region you select and is encrypted in transit with TLS 1.2+ and at rest with AES-256.
We run a formal incident-response program with continuous monitoring. If an incident affects your data we notify you promptly, in line with GDPR and our contractual obligations, and share what happened and the steps we took.
Yes. We sign a Data Processing Agreement on request and maintain a current list of the subprocessors we rely on, so your legal and security teams always have full visibility.