We hold ourselves to the bar we test others against.
Security is our product and our practice. Here's how we think about protecting your data — and how to get our full security documentation.
Principles we operate by.
Your data stays yours
We don't sell customer data, and assessment results are scoped to you. Access is least-privilege by default.
Encrypted in transit and at rest
Customer data is protected with strong encryption throughout the platform.
Held to the bar we test
We run our own security program to the same standard we assess our customers against.
Accessible by design
Our reports are tagged PDF/UA-1 so they work for screen-reader users, too.
Responsible disclosure
Found something? We welcome coordinated disclosure — reach out and we'll work with you.
Documentation on request
Need our security package, subprocessor list, or a DPA? Get in touch and we'll share it.
Specific attestations and certifications are shared under our security documentation on request. We don't publish compliance claims we haven't verified.