SECURITY
Security built around your decisions.
LAST UPDATED - JUNE 23, 2026
AT REST
AES-256
Encrypted storage for decisions and context
IN FLIGHT
TLS 1.3
Encrypted traffic in production
ISOLATION
RLS
Per-account row-level data isolation
CONTROLS
What protects your data
Encryption everywhere
Tenant isolation
Key separation
Authentication
Backups
No model training
DEVELOPMENT
Secure development practices
- Validate every public API input before business logic runs.
- Keep authentication and authorization checks at route boundaries.
- Apply least-privilege access to service keys and infrastructure.
- Avoid logging customer decisions, linked context, or provider secrets.
- Run dependency, type, lint, and build checks before production changes ship.
COMPLIANCE
Where we are today
IN PROGRESS
SOC 2 Type II
Controls are being mapped and evidence is being collected. A completed audit report is not currently published.
EXPORT & DELETE
Data rights
Export your decisions or request full account deletion at any time from Settings.
ACCESS
Least privilege
Service keys and infrastructure access are scoped to the minimum needed to operate the Service.
CUSTOMERS
How to help keep your account secure
ACCOUNTS
Protect credentials
Use strong passwords, avoid shared accounts, and rotate keys if exposure is suspected.
DECISIONS
Capture the why
Record the context, reasoning, alternatives, and consequences so the decision still makes sense months later.
DISCLOSURE
Report issues quickly
Send security findings through the vulnerability disclosure page.