We'd rather tell you exactly what's in place today than list certifications we don't hold. Here's the real picture.
The mechanisms actually enforced today, plus what's actively being built
We don't run a formal bug bounty program yet, but we take reports seriously and will respond to genuine, responsibly-disclosed findings.
Steps to reproduce, and what data or access it exposes.
Before any public disclosure, so real tenants aren't put at risk.
Reach out through the contact form and mark it as security-related — that gets it to the right person directly rather than sitting in a general queue.
Contact usWhat we can honestly commit to today
You retain ownership of your data. We process it only to provide the service — we don't sell it or share it with third parties for marketing purposes.
Every tenant's records are isolated at the database layer via row-level security — the isolation is enforced by Postgres itself, not just by application logic.
Ask us directly — we'd rather give you a straight answer than a compliance badge.