How the service is built and what we do when something goes wrong.
Last updated · 21 August 2026
All traffic is TLS 1.2 or above. Channel credentials are encrypted with envelope encryption backed by a managed key service, so a database copy on its own does not expose them.
Every business is a separate tenant. Queries are scoped by tenant at the data layer, not only in application code.
Staff access to production is limited to the people who need it, is authenticated separately from customer accounts, and is logged.
Email [email protected]. We will acknowledge within one working day. We do not currently run a paid bug bounty, but we credit researchers who report responsibly.