SECURITY

Security posture, as it actually stands.

We describe what we have built today and what remains in progress. We do not claim certifications, uptime SLAs, recovery objectives, breach-notification deadlines, or retention terms that current evidence does not support. For a full first-pilot security overview or a customer questionnaire, please contact us.

AUTHENTICATION
Pilot users sign in with a passwordless magic link — no local password, no password reset. Enterprise SSO (SAML 2.0 / OIDC) is planned for Phase 1 and configured per customer.
SOC 2 STATUS
We have implemented controls across identity, tenant isolation, encryption, secrets, audit logging, and CI policy. A SOC 2 audit has not been completed; no Type I or Type II report exists yet.
TENANT DATA
The pilot minimizes employee personal data — opaque tokens plus limited work location and plan facts. Names, government identifiers, home addresses, birth dates, and personal email addresses are not accepted through the standard roster path.
ENCRYPTION
Public traffic is served over HTTPS. GCP encrypts stored service data at rest. Selected sensitive application fields (stored email addresses, support message content) also use application-level AES-256-GCM encryption; secrets live in GCP Secret Manager, not source.
AUDIT LOGGING
Security-relevant and customer-administration mutations write append-only, tenant-scoped audit events. Access to internal audit views is itself audited, and application logging is structured to exclude plaintext personal data.
WHERE IT RUNS
The primary production configuration is GCP `us-central1`. This is a configuration fact today, not a contractual data-residency commitment; any residency, sub-processor, or DPA terms come from an executed customer agreement.
Security — ModuEquity