Security

Production data deserves the boring kind of security.

Encryption in transit and at rest, SSO with RBAC, audit logs, region pinning, and a responsible-disclosure path that doesn't require chasing us on Twitter.

For the full technical detail — key rotation, sub-processors, retention schedules, deletion workflow — see the security reference in docs →

Pillars

Six things we get right, before anything else.

Encryption everywhere
TLS 1.3 in transit. AES-256-GCM at rest for events, replays, attachments, and config payloads. Per-project encryption keys, rotatable.
Identity & access
SSO (SAML 2.0, OIDC) on Growth and Enterprise. RBAC at the project, team, and resource level. Audit log of every read and write, export to S3 on Enterprise.
Data residency
Cloud tenants pin data to EU, US, or AF regions on signup. Enterprise tenants can run air-gapped on their own infrastructure, with the same binary.
Secret handling
API keys are scoped per environment and never logged. Server-side keys live behind your own KMS; we don't see them. Replay PII is masked at capture, not in storage.
GDPR-ready operations
Right-to-access, right-to-erasure, and portability endpoints on the engine API. DPAs available on Pro and above. Sub-processor list published and versioned.
Responsible disclosure
[email protected] for vulnerability reports. We acknowledge within 24 hours and ship a fix or mitigation per severity. No bounties yet — credit instead.
Attestations

Honest about what we hold today.

We don't claim certifications we don't have. This list is kept current as audits progress.

GDPR-ready
Operational
Today
SOC 2 Type II
In progress
Q4 2026 target
ISO 27001
Roadmap
2027
HIPAA / BAA
On request
Enterprise only

Need a DPA, sub-processor list, or pen-test summary?

Email [email protected] and we'll send the latest signed copies.

Email [email protected]Compliance posture