Skip to content
Natuleadan

Search

Type to search the whole site

Security

Updated

This page explains how the platform protects your data and your work. Physical isolation per space, encryption in transit and at rest, and least-privilege access.

Request a security review

Write to us and we will answer with the scope and the available documentation.

Compliance

  • SOC 2 No
  • ISO/IEC 27001 No
  • PCI DSS No
  • HIPAA No
  • GDPR Yes
  • LOPDP Yes

Overview

Yes

Every space is a separate database; nothing is shared. We encrypt in transit and at rest and grant the least access needed to work.

Compliance

In progress

We comply with Ecuador's data protection law (LOPDP) and the GDPR where it applies. We do not yet hold certifications , neither SOC 2 nor ISO 27001 , and we do not announce them until we do.

Documents

In progress

Security reports and questionnaire answers are provided to customers under a confidentiality agreement.

Product Security

Yes

The HTTP surface lives in the API; the user panel renders without API calls. Authentication is self-hosted Better Auth, with MFA and passkeys.

Data Security

Yes

Every space has its own database in Turso, so isolation is physical and not a row among thousands. Backups go to Backblaze B2.

App Security

Yes

Cookie sessions for the web, Bearer tokens for mobile and agents, and server-side checks on every action. What is drawn is courtesy; what is cut is the action.

AI

Yes

Inference runs on external providers. We do not train models on your data, and an agent cannot see another agent or its owner.

Data Privacy

Yes

We collect the minimum, which is identity, usage and what you upload. You can request access, correction and deletion. We keep it for as long as you keep your account.

Access Control

Yes

Per-space roles (owner, admin, member) and per-company API keys. Third-party secrets are write-only, stored encrypted and never returned.

Infrastructure

Yes

Fully managed, with no servers of our own. Each provider below plays one role, and nothing of yours is shared with it beyond that.

Network Security

Yes

All traffic goes over TLS. Outgoing webhooks are signed, and access tokens are issued on demand and expire.

Policies

In progress

Security, acceptable use and incident response policies, published alongside the terms and conditions.

Incident Response

In progress

An incident is investigated, contained and communicated to those affected according to law and contractual deadlines.

Risk Management

Yes

Risk is reviewed by design, and billing is prepaid by credits, so there is no postpay and no accumulated debt.

Business Continuity

Yes

Encrypted backups in B2 and an independent database per customer, so one space's failure does not drag down the rest.

Change Management

Yes

Every change goes through a pull request, pre-commit validation and tests; deployment is done with the Vercel CLI.

Documents

The legal documents are published on this site; reports and questionnaire answers are shared with customers under a confidentiality agreement.

Subprocessors

Third parties that process data for us, and the role they play.

Turso Database per space
Vercel Deployment and compute
Upstash Queue, cache and blob
Backblaze B2 Backups
Resend Transactional email
Payphone Payments
Better Stack Observability and status
DeepInfra Model inference

Updates

  1. 2026-10-02

    First publication

    The Security page is published with the reference sections, honesty about certifications and our subprocessors.

  2. 2026-10-02

    Certifications

    We state that there is no SOC 2 or ISO 27001 yet; we announce no certification we do not hold.

  3. 2026-10-02

    Subprocessors

    Initial list of subprocessors and their role.