Trust centre
The controls we run, stated plainly
How we protect the service and your data, organised by the SOC 2 Trust Services Criteria for security, availability and confidentiality.
Where we stand
We do not hold a SOC 2 report. SOC 2 is an attestation by an independent auditor (a licensed CPA firm) that controls are suitably designed (Type I) and, over a period of months, operated effectively (Type II). No software can be "SOC 2 compliant" by itself. What follows are the controls we operate and collect evidence for, so that an audit can take place; it is not a certification and should not be read as one.
Each control is marked in place when it is implemented and its automatic check, where there is one, is passing; otherwise it is marked in progress.
Security (common criteria)
| Control | What it means | Status |
|---|---|---|
| Security policies approved and reviewed CC1.4, CC5.3 | Written information security policies, approved by management, reviewed at least yearly and available to staff. | In progress |
| Security awareness training CC1.4, CC2.2 | Everyone with access completes security awareness training when they join and every year. | In progress |
| Risk assessment CC3.1–CC3.4 | A yearly risk assessment covering threats, fraud and changes to the service, with treatment decisions recorded. | In progress |
| Two-step sign-in enforced for staff CC6.1 | Every staff account must use two-step sign-in (Security → Policies). | In progress |
| Password policy CC6.1 | Long passwords, checked against known breaches, with lockout after repeated failures. | In progress |
| Session timeout CC6.1 | Idle sessions end automatically (Security → Policies → idle timeout). | In progress |
| Periodic access reviews CC6.2, CC6.3 | Staff access reviewed every quarter and workspace administrators every six months, with sign-off. | In progress |
| Access removed when people leave CC6.2 | Leavers' staff accounts are disabled the same day; recorded in the audit log. | In progress |
| Application firewall and blocking CC6.6 | Attack detection with automatic blocking is on and out of learning mode. | In progress |
| Failed sign-ins monitored CC7.2 | Failed sign-ins are logged, accounts and addresses lock out, and staff are alerted to attacks. | In progress |
| Tamper-evident audit log CC7.2 | Security-relevant actions are logged append-only with a hash chain that is verified and exported. | In progress |
| Audit log retention CC7.2 | Audit entries are kept for at least a year (they are never pruned). | In progress |
| Dependency updates and vulnerability scanning CC7.1 | Dependencies are updated at least quarterly and scanned (composer audit, npm audit). | In progress |
| Incident response and breach register CC7.3, CC7.4 | An incident response plan, and a breach register that tracks the 72-hour notification deadline. | In progress |
| Change management CC8.1 | Changes are reviewed and tested before release; production runs with debugging off. | In progress |
| Vendor and sub-processor management CC9.2 | Sub-processors are listed publicly and reviewed every year. | In progress |
Availability
| Control | What it means | Status |
|---|---|---|
| Recent backups A1.2 | Daily database and file backups complete, with off-site copies. | In progress |
| Backups verified and restore tested A1.3 | Backups are verified automatically; a restore is tested at least every quarter. | In progress |
| Availability monitoring A1.1 | Components are checked continuously and incidents are published on the status page. | In progress |
Confidentiality
| Control | What it means | Status |
|---|---|---|
| Secrets encrypted at rest CC6.1, C1.1 | Platform settings and API keys are encrypted with the application key; two-step secrets are encrypted. | In progress |
| Encryption in transit CC6.7 | The service is only offered over HTTPS, with secure cookies and HSTS. | In progress |
| Data disposed of on schedule C1.2 | Retention periods are set per kind of data and a daily job deletes what is past them. | In progress |
| Data inventory (records of processing) C1.1 | What personal and confidential data is processed, why, where and for how long (GDPR Art. 30). | In progress |
Privacy and GDPR
- Your rights are self-service under Account → Privacy: download your data (JSON and CSV), correct it, restrict or object to optional processing, and erase your account. Requests that need us are answered within 30 days.
- We keep records of processing (GDPR Art. 30), retention periods per kind of data with automatic deletion, and a breach register that tracks the 72-hour notification deadline.
- 1 sub-processor(s) are listed on our sub-processors page. Workspace owners can review and accept our data processing agreement.
- Optional cookies load only after consent; you can change your choice at any time with Cookie settings.
More detail on how the application itself is built is on the security page. To report a vulnerability, see Report a vulnerability.