Tenant-scoped access
Authenticated requests resolve a company context before protected data is accessed.
Security
This page summarizes controls visible in the current product. A customer-specific security or data-processing review is available on request.
No third-party certification is currently claimed.
Authenticated requests resolve a company context before protected data is accessed.
Roles, effective permissions, subscription state, and feature gates protect supported operations.
Lifecycle events use per-company HMAC-SHA256 signatures over the exact request body.
Supported fields use configurable encrypted or hash-only storage behavior.
Data handling
Designated fields support AES-256-GCM encryption or keyed HMAC-SHA-256 hash-only storage. Displayed values are code defaults, not a customer’s live configuration.
Product authentication, tenant boundaries, supported permission checks, configured storage behavior, and assessment records.
Lawful data collection, secret storage, retention choices, fallback behavior, customer communication, and final business decisions.
Contact us for current security, privacy, or data-processing material. Never send credentials, tokens, signing secrets, or raw customer data by email.