Security

Enterprise-grade security by default.

The controls auditors ask for — wired up before you write a line of code.

JWT authentication

Industry-standard signed tokens with rotation and revoke. Public-key verification supported.

Two-factor authentication

TOTP-based 2FA enforced per role with backup codes and trusted devices.

Role-based access control

Granular roles with inheritance, scoped per workspace, project, and resource.

Row-level security

Per-row policies enforced at the database layer — not just the API.

Domain whitelisting

Restrict access by corporate email domain, IP range, or country.

Activity logs

Every read, write, and configuration change captured with actor + timestamp.

Rate limiting

Per-key and per-IP rate limits with burst protection and abuse alerts.

Compliance ready

Designed for governed environments, helping teams enforce operational controls, secure access management, and complete auditability.

99.99%
Uptime SLA on Enterprise
AES-256
Encryption at rest
TLS 1.3
Encryption in transit