Data handling & access controls
- Least-privilege access for systems and production data.
- Secrets stored in managed secret storage (GCP Secret Manager).
- Encrypted data in transit and at rest when supported by providers.
- Audit logging for sensitive operations and admin access.
Availability & reliability
- Cloud Run deployment with automated rollouts and health checks.
- Monitoring endpoints and alerting for uptime visibility.
- Backup and recovery procedures for critical data stores.
Compliance documentation
We provide documentation on request for procurement or vendor security reviews, including a Certificate of Insurance (COI) and security questionnaires.
Responsible disclosure
If you discover a security issue, please contact us immediately. We appreciate responsible disclosure and will respond promptly.