Skip to main content

Vendor Security Packet

Last updated: March 2026

This page consolidates all security, compliance, and data protection documentation for enterprise procurement and security review teams. Everything a vendor security reviewer needs is linked from here.

Our Security Posture (Honest Summary)

What we have:

  • SOC 2-certified infrastructure providers
  • TLS 1.2+ encryption, AES-256 at rest
  • OAuth 2.0 via GitHub/Google
  • RBAC with 4 org roles + superadmin
  • Tenant isolation at query level (49 routes)
  • Audit logging, Sentry error monitoring
  • Rate limiting (Redis, fail-open)
  • Deterministic compliance engines
  • GDPR-aligned DPA with SCCs

What we don't have yet:

  • SOC 2 Type II audit (in progress)
  • ISO 27001 certification
  • Third-party penetration testing
  • SAML-based SSO
  • MFA enforcement at app level
  • Multi-region deployment
  • Staging environment
  • Formal DR drill testing

Core Documents

Additional Resources

Questions?

Our security team is available to answer detailed questions about our infrastructure, compliance posture, and security practices.