Security overview
Reflects the current configuration of the platform, not a static document.
Authentication
- Methods enabled
- SSO (SAML), Email + password, Google
- MFA
- Required for all admin roles
- Session lifetime
- 8 hours, refresh required
- Password leak check
- Enabled (HIBP)
Access control
- Model
- Role based with row level security
- Roles
- Owner, Admin, Operator, Reviewer, Viewer
- Approval workflows
- Required for production policy changes
- Service accounts
- Scoped per integration, rotated 30 days
Encryption
- In transit
- TLS 1.3 enforced everywhere
- At rest
- AES 256, customer managed keys available
- Secrets
- Vault backed, never in logs
- Field level
- PII columns encrypted with separate keys
Infrastructure
- Region
- EU West, sovereign by default
- Isolation
- Per tenant schemas, no shared rows
- Monitoring
- 24/7 alerting, on call rotation
- Backups
- Point in time, 35 days retention
Everything on this page is generated from the live state of your platform. If a policy changes, an agent runs, or data flows, this page reflects it. Trust becomes automatic, not assembled.