Security

Security for production workloads

Controls teams expect when orchestrations touch customer and operational data.

Encryption

Data encrypted in transit and at rest. Secrets stored in an app-level vault.

Multi-tenant RBAC

Workspace permissions and tenant isolation from day one.

Audit and trace

JSON logs with traceId, tenantId, and userId on requests and flow runs.

Auth hardening

Argon2id password hashing, JWT refresh rotation, OAuth2 for connectors.

Compliance

Architecture aligned with SOC 2 Type II, GDPR, HIPAA, and ISO 27001 practices.

Network controls

IP allowlists, webhook signature checks, and rate limits on public endpoints.

Request the security pack

We can share our SOC 2 summary, pen test overview, and architecture notes.