Security

Production-grade controls, explained plainly.

We build billing pipelines that touch carrier data, employer groups, and financial systems. The security posture below is what makes that responsibly possible.

Encryption in transit

TLS 1.3 for all traffic between clients, pipelines, and integrated systems.

Encryption at rest

AES-256 for all stored data, including backups and reconciliation snapshots.

Isolated infrastructure

Runs on Hetzner with full network isolation per customer environment.

Backups + failover

Regular automated backups with point-in-time recovery and automated failover.

Role-based access control

Least-privilege RBAC for all pipeline and console access. Full audit trail.

No data used for training

Customer data is never used to train or fine-tune models. Ever.

Compliance

Where we are. Honestly.

In progress
SOC 2 Type II

SOC 2 is in progress. In the meantime, our current controls cover encryption, access management, backups, monitoring, and incident response. We can share our control documentation under NDA during a review.

Availability
99.9%+ uptime SLA (Enterprise)

Enterprise plans include a 99.9%+ uptime SLA with on-call response. Lower tiers run on the same infrastructure but without a contractual SLA.