Company / Security

    Enterprise-grade by default.

    SOC 2-aligned controls, encryption in transit and at rest, SSO, role-based access, and regional data residency for global operators.

    Security Features

    Built-in protection, top to bottom.

    Encryption at Rest and in Transit

    All data is encrypted using AES-256 at rest and TLS 1.3 in transit. Customer data is isolated at the storage layer with per-tenant encryption keys.

    Single Sign-On (SSO)

    Support for SAML 2.0 and OIDC-based SSO, enabling integration with Okta, Azure AD, Google Workspace, and any standards-compliant identity provider.

    Role-Based Access Control (RBAC)

    Granular permissions at the site, role, and data level. Define custom roles with least-privilege access to ensure users see only what they need.

    Audit Logging

    Every action is logged with timestamps, user identity, and context. Logs are immutable and retained for 12 months for compliance and forensics.

    Regional Data Residency

    Data is stored in the region of your choice (US, EU, UK, or APAC). We support data locality requirements for regulated industries and government contracts.

    SOC 2 Compliance

    Our controls are designed to align with SOC 2 Type II criteria. Annual audits validate the effectiveness of our security, availability, and confidentiality safeguards.

    Standards & Compliance

    Built to meet global standards.

    SOC 2 Type II

    Security, availability, and confidentiality controls audited annually

    ISO 27001

    Information security management system framework (in progress)

    GDPR

    Data protection and privacy compliance for EU users

    AES-256

    Encryption standard for data at rest

    TLS 1.3

    Encryption protocol for data in transit

    SAML 2.0 / OIDC

    Industry-standard authentication protocols

    FAQ

    Security questions.

    You choose your data region during onboarding. We currently offer data residency in the United States, European Union, United Kingdom, and Asia-Pacific (Singapore). Data is stored in SOC 2-compliant cloud infrastructure with isolated storage per tenant.

    Have specific security requirements?

    Our security team can share our SOC 2 report, penetration testing results, data processing agreement, and answer any questions about our architecture.