Security
Last updated 2026-09-26
Encryption
Data is encrypted in transit (TLS) everywhere. Each customer organization has its own data encryption key, wrapped by a cloud key-management service; that key protects channel access tokens, other sensitive fields, and archived data. Deleting an organization destroys its key, so any remaining encrypted copies become permanently unreadable once backups age out.
Tenant isolation
Every customer organization's data is isolated at the database layer — not only in application code — using row-level security enforced by the database itself, on every table that holds customer content. Application queries can't accidentally (or maliciously) read across organizations, and this is verified by an automated test suite on every change.
Support access with consent
Our staff do not have standing access to customer data. Access requires a time-limited, logged grant, and — depending on your organization's chosen policy — your explicit approval before a staff member can view your data. You can see every pending and past support-access grant against your organization from your settings.
Audit logs
Every state-changing action — by your team, by our staff under a support grant, or by automated jobs — is written to an append-only audit log. Your organization's own audit log is visible from your settings; platform-wide staff actions are recorded in a separate, hash-chained log we use internally to detect tampering.
Reporting a vulnerability
If you believe you've found a security issue, please email privacy@example.com with details. We ask that you not access or modify data that isn't yours while investigating.