Security
Read first, answered first.
We run our own products in production and treat client systems with the same care. Here is how we work, and how to reach us if you find a problem.
01 — How we work
Our practices.
- Least privilege
- Production access is limited to the people who operate a system, reviewed when roles change.
- Encryption
- Data is encrypted in transit everywhere, and at rest on the platforms that store it.
- Separation
- Client environments, product environments and internal tooling are kept apart. Client code never trains or feeds our products.
- Dependencies
- We keep dependencies current and monitor advisories for everything we run in production.
- Backups
- Databases we operate are backed up automatically, and restores are tested rather than assumed.
- People
- Small team, hardware-key two-factor on the accounts that matter, and no shared credentials.
02 — Disclosure
Found a vulnerability?
Report it to [email protected]. Include what you found, where, and how to reproduce it. We acknowledge reports within 48 hours, keep you informed while we fix, and credit researchers who want credit. Please give us reasonable time to fix before disclosing publicly, and do not access data that is not yours.