Skip to content

Security

Project data is sensitive: budgets, contracts, supplier prices. Here is what protects it, described as it is today. We claim nothing we cannot show.

Isolation between organisations

Every record belongs to one organisation, and the database itself refuses to show it to anyone outside — enforced by row-level security on every table, not only by the application. Roles narrow this further inside an organisation.

Encryption

Traffic is encrypted in transit (HTTPS with strict transport security). Data is encrypted at rest by our database and storage provider. Uploaded documents sit in a private bucket and are opened through signed links that expire after an hour.

Sign-in

Passwords are stored only as salted hashes by our authentication provider. Two-step verification with an authenticator app is available to everyone, and you can sign out all other devices at any time.

Payments

Card details go directly to Stripe. We never see or store them.

Accountability

An activity log records member, role, project and subscription changes. Every change of a task, budget or record also keeps its author and time.

Your data, your control

Export your personal data and delete your account yourself. Project data can be exported as CSV and Excel at any time.

Where it runs

Database, authentication and file storage: Supabase, Canada (Montréal, AWS ca-central-1). Application hosting: Netlify. Transactional email: Brevo, European Union. Payments: Stripe. The full list, with purposes, is in our Data Processing Addendum.

What we haven't done yet

We are not certified SOC 2 or ISO 27001 today and we do not claim to be. If you need a security questionnaire answered or a specific region, write to us.

Found a vulnerability? Please tell us privately at the address in our security.txt before disclosing it. We acknowledge reports within 3 working days.

Data processing addendum