Skip to content

Security, in plain English.

An audit platform holds the most sensitive file in a company. Here is what we do about that — and what we don't do yet.

How we protect your work

Four things we can point at.

Your workspace is isolated at the database layer — every query carries your workspace and only your workspace.

Auditee links are 40-character random tokens scoped to one review's open requests; regenerate or disable them any time.

Files are type-checked, size-limited and hashed on arrival; every upload is stamped with its source.

Every mutation writes an activity event — the platform keeps its own audit trail.

What we don't do yet

  • App-based 2FA
  • SSO
  • Custom retention windows
  • On-premise deployment

They're on the roadmap, and we'd rather tell you than let you assume.

Have a security question this page doesn't answer? Ask it — we would rather have the conversation than have you guess.

Ask us a question