Enterprise-grade security
We’ve made security our core focus from day one to safeguard your company data, IP and workspace privacy.
Compliant by design
GDPRIn force
SOC 2 Type IICertification in process
ISO 27001Certification in process
EU hostingIn place today
How your data is held, reached and used
Trusted data storage
Each customer runs in their own tenant, in the region you choose, encrypted on the way in and out, on infrastructure that is itself SOC 2 and ISO 27001 compliant.
- Single-tenant isolation
- Data residency by region
- Data encryption in transit
- Hosted on SOC 2 & ISO 27001 compliant infrastructure
Access on your terms
Your identity provider stays the source of truth. Sensitive data is detected before it moves, and every action is written to an audit log.
- SSO / SCIM provisioning
- Sensitive-data detection
- Audit logging
- Advanced RBAC on roadmap
Agents inside guardrails
An agent that can commit spend raises a different question from one that reads documents: not who can see this, but what it can do without you.
- Approval thresholds
- You set the amount above which an agent stops and asks. Below the line it acts; above it, a named person signs.
- Never unilateral
- Awarding a contract, changing supplier bank details, releasing payment, onboarding a new supplier. The agent prepares them; a person commits them.
- On the record, before it leaves
- Every action is a recorded event with an actor, a reason and a timestamp. Nothing reaches a counterparty until a person has approved it.
- Escalation to a human
- Out of policy, out of scope, or simply uncertain: the agent stops and hands the decision back with its reasoning attached.
Documentation
Sub-processors, the DPA and our security measures are published in the trust center and kept current there.
FAQ
In transit and at rest, on infrastructure that is itself SOC 2 and ISO 27001 certified.