Security

Security is part of the product design, not a feature on top.

Your workspace is yours alone
Every workspace is isolated from every other, enforced in two independent layers and tested automatically on every release.
No passwords, phishing-resistant options
Sign in with an email link, Google, or a passkey. Add an authenticator app for two-factor authentication; workspaces can require it.
Least privilege everywhere
Each part of the system can reach only the data it needs, and our own support tools see only what a support request requires.
Secrets stay out
We never store API key or license values, only their metadata, and reject pasted secrets.
Verified billing events
Every payment event is verified before we act on it, and processed exactly once.
Secure by default
Encrypted connections only, hardened browser protections, rate limiting, and an audit log of every important action.

Report a vulnerability

Email [email protected]. We acknowledge reports within 3 business days and will not pursue good-faith research that follows our disclosure policy. See also security.txt.