Legal
Security
Security is foundational to a governance product. Here's how we protect your data and operate the platform.
Last updated: June 6, 2026
Our approach
We hold ourselves to the standards we help our customers meet. Security is designed into the product and our operations from the start, not bolted on.
Encryption
All data is encrypted in transit with TLS and at rest using industry-standard algorithms. Secrets are managed through a dedicated secrets manager, never stored in source code.
Access control
We enforce least-privilege access with role-based permissions and require multi-factor authentication for internal systems. Production access is logged and reviewed.
Monitoring and response
We continuously monitor our infrastructure for anomalies and maintain an incident response process so issues are detected, contained, and communicated quickly.
Compliance
Our controls are aligned with leading frameworks including SOC 2 and ISO/IEC 27001. We're happy to share more detail with customers under NDA.
Resilience and backups
Customer data is backed up regularly and restoration is tested. We design for high availability and maintain a documented business continuity and disaster recovery plan.
Subprocessors
We work with a small, carefully vetted set of subprocessors to deliver the service. Each is held to data-protection obligations consistent with our own, and the current list is available on request.
Reporting a vulnerability
If you believe you've found a security issue, please reach out via our contact page. We investigate every report and appreciate responsible disclosure.
Questions about this page? Reach our team via the contact page. This is a product template and not legal advice.