SECURITY
Security posture, as it actually stands.
We describe what we have built today and what remains in progress. We do not claim certifications, uptime SLAs, recovery objectives, breach-notification deadlines, or retention terms that current evidence does not support. For a full first-pilot security overview or a customer questionnaire, please contact us.
- AUTHENTICATION
- Pilot users sign in with a passwordless magic link — no local password, no password reset. Enterprise SSO (SAML 2.0 / OIDC) is planned for Phase 1 and configured per customer.
- SOC 2 STATUS
- We have implemented controls across identity, tenant isolation, encryption, secrets, audit logging, and CI policy. A SOC 2 audit has not been completed; no Type I or Type II report exists yet.
- TENANT DATA
- The pilot minimizes employee personal data — opaque tokens plus limited work location and plan facts. Names, government identifiers, home addresses, birth dates, and personal email addresses are not accepted through the standard roster path.
- ENCRYPTION
- Public traffic is served over HTTPS. GCP encrypts stored service data at rest. Selected sensitive application fields (stored email addresses, support message content) also use application-level AES-256-GCM encryption; secrets live in GCP Secret Manager, not source.
- AUDIT LOGGING
- Security-relevant and customer-administration mutations write append-only, tenant-scoped audit events. Access to internal audit views is itself audited, and application logging is structured to exclude plaintext personal data.
- WHERE IT RUNS
- The primary production configuration is GCP `us-central1`. This is a configuration fact today, not a contractual data-residency commitment; any residency, sub-processor, or DPA terms come from an executed customer agreement.