Trust
Live practicesPrivacy practices on the product spine
Tenant-scoped data, role-gated access, and audit for mutating actions. Legal policy text lives under Legal.
Tenant-scoped stores
Customer operational data is bound to tenant context. Staff access is gated by membership and RBAC, not shared global tables without filters.
Least privilege by plane
Platform operators and tenant users do not share a permission soup — planes and permissions are data, enforced in services.
See also
The Privacy Policy (draft for legal review) describes commitments in policy language. This page describes engineering posture.
Talk security with us
Request a security package, questionnaire answers, or DPA discussion — no fake seals on this site.