Security

Built for regulated work, described honestly.

Redundant tenant isolation, a cryptographic audit chain, agent-level data scrubbing, and an approval gate on every external side effect. Below: what is enforced in the product today, and — separately — what is designed but not yet in force.

Enforced today

TLS in transit

HTTPS everywhere, TLS 1.3 where the client supports it. Database connections are encrypted; CA verification is configurable per environment.

Encryption at rest

Provided by our managed database and object-storage providers. Application-level field encryption is on the roadmap, not yet shipped.

Redundant tenant isolation

Application query scoping → Postgres row-level security → Neo4j tenantId. A CI job connects as the constrained app role and proves org A cannot read or write org B.

Append-only audit log

The app database role has no UPDATE or DELETE on audit_log. Rows carry a SHA-256 hash chain with a verifier that detects gaps and tampering.

Provenance on every fact

Every UI fact carries a source. Unattributed facts fail review — a surface with no evidence renders an empty state instead of a number.

Agents draft, humans approve

No outbound message, contract, invoice, or trust-tier change takes effect without an explicit human approval step, recorded in the audit log.

PHI is gated, not incidental

The Compliance Sentinel blocks PHI access outside a HIPAA-mode workspace and requires a recorded justification. PHI is never placed in a model prompt, and error telemetry is scrubbed before it leaves the process.

Coordinated disclosure

Report a vulnerability to [email protected] and we respond within one business day.

Not yet in force

We would rather lose a deal than win one on a control we do not have. Ask us about any of these and we will tell you exactly where it stands.

SOC 2

Not certified. No observation window has started. The controls above are the groundwork; we will publish the auditor and timeline when engaged.

Third-party penetration test

Not yet performed. Planned before the first enterprise deployment.

Field-level encryption

Specified for rate, compensation, and PHI fields (docs/05). Not implemented today.

Continuous compliance monitoring

No monitoring vendor is in place yet.

24/7 on-call

Incident response is documented and severity-classified, but round-the-clock paging is not staffed yet.

Sub-processors

Supabase (auth + Postgres), Groq (primary LLM), OpenAI (embeddings), Resend (email), Stripe (payments), Sentry (telemetry), S3/R2 (storage). The full list and what each one receives is in our Privacy Policy.

Read the privacy policy →

HIPAA + GxP modes

Workspace-level compliance mode is built: PHI stays out of model context, GxP mode gates regulated actions, and e-signature records capture signer, timestamp, and meaning. A BAA is required before PHI enters a workspace — talk to us first.

Discuss a BAA →

Disclosure

Found a vulnerability? Coordinated disclosure with thanks. We acknowledge within one business day.

[email protected] →