Security
Safe and secure
Security is paramount to us. We work hard to follow best practices and are fiercely protective of your data.
How we protect you
Secure by default
The practices we hold ourselves to, from the data center to the last byte at rest.
ISO & FedRAMP data centers
Our data centers follow a standardised approach to security, risk assessment, authorisation, and continuous monitoring — essential for organisations of every size.
HTTPS and HSTS everywhere
All client-to-server and server-to-server traffic runs over TLS, and HSTS forces browsers onto HTTPS, so nothing quietly falls back to plain HTTP.
Limited production access
A clear process limits who can touch production. Only a small set of verified, trusted people have access; everyone else works in simulated environments.
Secure payments
Our payments provider, Stripe, is certified to PCI Service Provider Level 1 — the most stringent certification available in the payments industry.
Backups deleted for privacy
Backups are encrypted and stored across multiple data centers with limited access. On request, we delete your data from those backups too.
Data encryption
All data is encrypted at rest with AES-256. Sensitive details — phone numbers, emails, OAuth tokens — are encrypted and never transferred in plaintext.
Questions about security?
Talk to our team about certifications, data handling, or anything on your security checklist.