← Back to Security overview

Security — Technical Implementation

Last updated: May 2026

The code that implements every claim below is AGPL-3.0 open source on GitHub. This is the engineering detail behind the commitments on the Security overview, our BAA, and our Privacy Policy. We keep the receipts here so the values you read are the values that ship.

In transit

At rest

Tenant isolation

Identity and access

AI processing

Audit logging and behavioral monitoring

Backup and retention

Egress allowlist

The application boundary is allowlisted to the subprocessors named in the BAA §5.2, our Privacy Policy §5, and the Where your data lives table on the Security overview. The weekly internal pentest probes for egress to non-allowlisted hosts; any finding is surfaced in the next dated pentest report and triggers a release hold while it is investigated. The release hold is operational today (an on-call engineer reviews the report and pauses release) — automating it as a hard CI gate is on our roadmap.