Template — not yet legally reviewed. This page is a placeholder that must be reviewed and finalized by qualified legal counsel before commercial launch.

Security Overview

SOC 2-style controls. We are not SOC 2 certified; this describes the controls we operate.

Access control

Role-based access (owner, admin, coach, member, viewer) with per-user data isolation, HttpOnly session cookies, CSRF protection, and rate-limited authentication. Enterprise SSO/SAML is supported via provider integration.

Data protection

TLS in transit, encryption at rest via our cloud provider, uploads validated by size, type, and magic bytes, optional ClamAV malware scanning with quarantine, and files stored outside any public path.

Audit logging

Append-only audit trail covering logins, uploads, AI generations, exports, billing, role changes, and admin access — exportable by administrators.

Monitoring

Liveness/readiness probes, structured logging with request IDs, error IDs surfaced to users, and Sentry-ready error reporting.

Backups

Daily database backups with restore testing procedures documented, plus configurable data-retention windows per organization.

Reporting a vulnerability

Email the security contact listed in the repository SECURITY docs. We ask for coordinated disclosure and respond as quickly as we can.

Questions? Contact support. See also: Privacy · Terms · Security · Subprocessors · DPA · Data deletion