Trust center

Your data, your customers, our obligation.

Security and compliance posture, in detail. Email [email protected] for SOC 2 reports, pen test summaries, or signed DPAs.

Security architecture

๐Ÿ” Encryption

TLS 1.3 in transit. AES-256-GCM at rest. Private keys: per-tenant isolation via Cloudflare KV metadata. Customer keys: self-custody option.

๐Ÿชช Identity

PASETO v4.public with Ed25519. Open IETF-aligned standard. No JWT alg-none disasters possible.

๐Ÿ“œ Audit chain

Append-only Merkle-chained audit log. Tamper-evident. Compliance & Audit Agent verifies chain every 10 min.

๐Ÿ›ก Infrastructure

Cloudflare Workers + D1 + KV + R2. DDoS-mitigated by default. SOC 2 Type II underlying. No public IPs.

Compliance roadmap

FrameworkStatusTarget
GDPR (EU)CompliantLive
CCPA (California)CompliantLive
SOC 2 Type IIn progressQ4 2026
SOC 2 Type IIPlannedQ2 2027
PCI DSSStripe-delegatedLive (via Stripe)
DPF (EU-US)PlannedQ4 2026

Disclosure policy

Vulnerability reports: email [email protected] with details + proof-of-concept. Acknowledged within 24h. Critical issues triaged within 4h. We do not run a paid bug bounty yet but we will publicly credit + send swag for confirmed issues.