Skip to content

Security

Controls that exist, described exactly.

Security pages usually list aspirations. This page lists what is implemented and active on this platform today, with a plain list of what isn't. Judge us by both.

What's implemented today

Identity and access

  • Passwords are stored only as Argon2id hashes; the plaintext never exists on our side.
  • Login is rate-limited per email and per address, with automatic lockouts on repeated failures.
  • Sign-in responses never reveal whether an account exists.
  • Password reset uses single-use, time-limited tokens.

Session integrity

  • Access tokens are bound to a server-side session that can be revoked instantly.
  • Refresh tokens rotate on every use; a replayed token invalidates the whole session, by design.
  • Idle sessions expire; logout revokes the session server-side, not just in your browser.
  • Session theft is detected structurally, not heuristically.

Isolation between companies

  • Every data query is scoped to your company by the server; the client cannot widen it.
  • Requests for another company's data return exactly the same response as nonexistent data.
  • Cross-company isolation is covered by automated tests that run against a real database on every release.
  • Roles and permissions are enforced server-side on every endpoint.

Records that can't be rewritten

  • The record of every action is append-only: no edit, no delete, for anyone, through any path.
  • Approval decisions, AI actions, and state changes are all recorded with who, what, and when.
  • Records survive backups and restores, so audits hold over time.

Financial integrity

  • Amounts are exact to the cent; no floating-point money anywhere.
  • Sent invoices cannot be modified, only credited.
  • A payment can never overpay an invoice; the math is enforced, not advisory.
  • Credit notes are linked to the invoices they adjust.

Platform and network

  • Only the standard web ports and SSH are reachable from the internet; every internal service is private to the server.
  • All hostnames serve HTTPS with automatic certificates from a public authority; plain HTTP redirects to HTTPS.
  • Inbound webhooks are verified by cryptographic signature before they're accepted.
  • Integration credentials are encrypted with a per-deployment key.
  • Server security updates are applied as part of routine maintenance.

What is not built yet

What is not built yet

The honest list. These are real gaps, and we treat them as such.

Multi-factor sign-in

Not yet available. Designed and scheduled; this page updates the day it ships.

Breached-password screening

Not yet active at sign-up. Planned together with MFA.

Independent audits (SOC 2, ISO 27001)

Not held. We have never claimed otherwise, and we won't until an audit is passed.

Customer-managed encryption keys

Not offered. Data is encrypted in transit and protected at the server level; per-company key management is a future item.

Operational discipline

Operational discipline

Security is also what happens after the code ships.

  • Daily automated backups, each verified after the run.
  • Weekly full-restore drills against the latest backup.
  • Health checks that distinguish a live process from a working service.
  • Deployments verified from outside the server before being declared complete.
  • Secrets and credentials in protected server configuration, never in source control.

Found something? Tell us.

Write to [email protected] with details. We read every report, fix what's real, and credit finders with their permission.