Everything your security team needs to review us, in one place, without a call. Where a control is not yet in place we say so and give you the date — an honest gap is easier to review than a vague claim.
Most vendors answer a security review by describing how well they guard your data. We would rather reduce what there is to guard. Three properties do most of the work.
We operate a safe-harbour policy. Report a vulnerability in good faith and we will not pursue legal action, will respond within one business day, and will credit you unless you would rather we did not.
PGP key and security.txt published at /.well-known/security.txt
Every claim on it about coordination — no duplicates, deterministic replay, signed history — is checkable by you, on your own machine, against a key we published before the run existed. A trust centre that asks for trust is a weaker document than one that hands you the evidence.