Security Overview
SOC 2-style controls. We are not SOC 2 certified; this describes the controls we operate.
Access control
Role-based access (owner, admin, coach, member, viewer) with per-user data isolation, HttpOnly session cookies, CSRF protection, and rate-limited authentication. Enterprise SSO/SAML is supported via provider integration.
Data protection
TLS in transit, encryption at rest via our cloud provider, uploads validated by size, type, and magic bytes, optional ClamAV malware scanning with quarantine, and files stored outside any public path.
Audit logging
Append-only audit trail covering logins, uploads, AI generations, exports, billing, role changes, and admin access — exportable by administrators.
Monitoring
Liveness/readiness probes, structured logging with request IDs, error IDs surfaced to users, and Sentry-ready error reporting.
Backups
Daily database backups with restore testing procedures documented, plus configurable data-retention windows per organization.
Reporting a vulnerability
Email the security contact listed in the repository SECURITY docs. We ask for coordinated disclosure and respond as quickly as we can.
Questions? Contact support. See also: Privacy · Terms · Security · Subprocessors · DPA · Data deletion