Security
Updated
This page explains how the platform protects your data and your work. Physical isolation per space, encryption in transit and at rest, and least-privilege access.
Write to us and we will answer with the scope and the available documentation.
Compliance
- SOC 2 No
- ISO/IEC 27001 No
- PCI DSS No
- HIPAA No
- GDPR Yes
- LOPDP Yes
Overview
YesEvery space is a separate database; nothing is shared. We encrypt in transit and at rest and grant the least access needed to work.
Compliance
In progressWe comply with Ecuador's data protection law (LOPDP) and the GDPR where it applies. We do not yet hold certifications , neither SOC 2 nor ISO 27001 , and we do not announce them until we do.
Documents
In progressSecurity reports and questionnaire answers are provided to customers under a confidentiality agreement.
Product Security
YesThe HTTP surface lives in the API; the user panel renders without API calls. Authentication is self-hosted Better Auth, with MFA and passkeys.
Data Security
YesEvery space has its own database in Turso, so isolation is physical and not a row among thousands. Backups go to Backblaze B2.
App Security
YesCookie sessions for the web, Bearer tokens for mobile and agents, and server-side checks on every action. What is drawn is courtesy; what is cut is the action.
AI
YesInference runs on external providers. We do not train models on your data, and an agent cannot see another agent or its owner.
Data Privacy
YesWe collect the minimum, which is identity, usage and what you upload. You can request access, correction and deletion. We keep it for as long as you keep your account.
Access Control
YesPer-space roles (owner, admin, member) and per-company API keys. Third-party secrets are write-only, stored encrypted and never returned.
Infrastructure
YesFully managed, with no servers of our own. Each provider below plays one role, and nothing of yours is shared with it beyond that.
Network Security
YesAll traffic goes over TLS. Outgoing webhooks are signed, and access tokens are issued on demand and expire.
Policies
In progressSecurity, acceptable use and incident response policies, published alongside the terms and conditions.
Incident Response
In progressAn incident is investigated, contained and communicated to those affected according to law and contractual deadlines.
Risk Management
YesRisk is reviewed by design, and billing is prepaid by credits, so there is no postpay and no accumulated debt.
Business Continuity
YesEncrypted backups in B2 and an independent database per customer, so one space's failure does not drag down the rest.
Change Management
YesEvery change goes through a pull request, pre-commit validation and tests; deployment is done with the Vercel CLI.
Documents
The legal documents are published on this site; reports and questionnaire answers are shared with customers under a confidentiality agreement.
Subprocessors
Third parties that process data for us, and the role they play.
| Turso | Database per space |
| Vercel | Deployment and compute |
| Upstash | Queue, cache and blob |
| Backblaze B2 | Backups |
| Resend | Transactional email |
| Payphone | Payments |
| Better Stack | Observability and status |
| DeepInfra | Model inference |
Updates
-
2026-10-02
First publication
The Security page is published with the reference sections, honesty about certifications and our subprocessors.
-
2026-10-02
Certifications
We state that there is no SOC 2 or ISO 27001 yet; we announce no certification we do not hold.
-
2026-10-02
Subprocessors
Initial list of subprocessors and their role.