Security

Last updated: 11 August 2026

How we keep your data separated, who can reach it, and what happens when something goes wrong. Where a measure lives in the code we say so, because a claim you can check is worth more than one you cannot.

One organisation cannot see another

Every row that belongs to a customer carries the organisation it belongs to, and the database enforces it: the tenant boundary runs through the data layer, not through the interface. A query without an organisation context returns nothing rather than everything — that is the safe direction to fail in.

The audit log is append-only. There is no update path and no delete path, so a record of what happened cannot be quietly rewritten.

Getting in

  • Passwords are stored as a scrypt hash, never as text, and a hash gives nothing back.
  • You can sign in with Google, Microsoft or GitHub instead; then we never see a password.
  • Sessions expire, and you can end them.
  • Email addresses are confirmed before an account becomes usable.

Who may do what

Roles decide what a person can see and do, and the check sits at the API rather than in the interface — hiding a button is not a permission. Viewers and customers do not cost a seat, so feedback never has to stay outside the board.

The same applies to the AI colleagues: each agent has a role with its own permissions, and no agent can widen them. An agent that may classify comments cannot change a status.

Keys and tokens

  • Model keys are stored encrypted and are never shown again after saving.
  • A model policy records which providers have a key, never the key itself.
  • A CI token belongs to one organisation and can be revoked and reissued at any time.
  • Tokens are never written to logs.

Transport and storage

All traffic runs over TLS. The database is encrypted at rest by [[hosting provider]] and backed up [[frequency]], with a retention of [[retention]]. [[Whether and how restores are tested.]]

What our staff can see

Access to production data is limited to the people who need it, and it is logged. We look at your project content when you ask us to help or when we are investigating a fault, and not otherwise.

When something goes wrong

If a breach affects your data we tell you without undue delay and within 72 hours of becoming aware. You get what we know, what we are doing about it, and what you can do. If we do not know something yet, we say that instead of waiting until the picture is complete.

Found a vulnerability? Report it to [[security contact address]]. We will not take legal action against anyone who reports a problem in good faith and gives us reasonable time to fix it.

What we do not claim

Last updated: 11 August 2026.