Our trust roadmap

Everything a security reviewer needs, published rather than requested: the controls enforcing your data today, the SOC 2 formalization work in flight, and the dates we are working to.

Controls in place today

  • Row-level security isolates every workspace at the database.
  • Passwordless email codes and enforced TOTP MFA on protected routes.
  • Append-only, immutable sign-offs with a content hash and server-captured timestamp.
  • Private assets served via short-lived signed URLs; secrets held server-side, never in the client bundle.
  • CI typecheck/lint/tests, CodeQL, secret-scanning, and Dependabot on every change.

The formalization work in flight

A written policy set, documented access-review cadence, a tested incident-response runbook, a risk register, and a tested backup restore.

Timeline (targets, not commitments)

Readiness assessment and policy remediation through 2026; a possible Type I in early 2027 and a Type II observation window later in 2027. No certification is complete until an independent auditor issues a report.

See also Security and the Trust Center.