Security
Security is part of the product design, not a feature on top.
- Your workspace is yours alone
- Every workspace is isolated from every other, enforced in two independent layers and tested automatically on every release.
- No passwords, phishing-resistant options
- Sign in with an email link, Google, or a passkey. Add an authenticator app for two-factor authentication; workspaces can require it.
- Least privilege everywhere
- Each part of the system can reach only the data it needs, and our own support tools see only what a support request requires.
- Secrets stay out
- We never store API key or license values, only their metadata, and reject pasted secrets.
- Verified billing events
- Every payment event is verified before we act on it, and processed exactly once.
- Secure by default
- Encrypted connections only, hardened browser protections, rate limiting, and an audit log of every important action.
Report a vulnerability
Email [email protected]. We acknowledge reports within 3 business days and will not pursue good-faith research that follows our disclosure policy. See also security.txt.