Security and data handling
What the product does to keep an organisation’s data separate and safe, stated plainly.
- Access
- By invitation only. People sign in with a one-time link sent to their email address. An owner can also create a password account for a person or a test account; sign-in attempts are rate limited and logged, and organisations can require two-factor.
- Two-factor
- Members can add an authenticator app. An organisation can require it, and a session without it is sent to set it up before it sees anything else. An owner can waive it for a named non-admin account for a stated reason and a limited time (180 days at most in total from the first time, and removing it does not restart the count); each waiver is recorded in the audit log and ends if the person becomes an admin or owner.
- Separation
- Every organisation’s data is held under row-level security in the database, so one organisation cannot read another’s, whatever the page asks for.
- Roles
- Owner, admin, analyst and viewer. Changing settings, members and integrations needs admin; viewers cannot change anything.
- Where data lives
- A managed Postgres database in the UK (London). The provider encrypts data at rest and in transit.
- What is collected
- Only what you add (domains, suppliers, software, device lists) and public threat sources. No agent is installed on your devices.
- In the browser
- A strict content security policy with per-request script nonces, no third-party scripts and no advertising or tracking cookies.
- Connections
- Outbound only, to public threat sources and the integrations you switch on. Keys you enter are stored server-side and never shown again.
Reporting a problem
Found something? Tell us through the security contact file or the request form on the front page. Please do not test against other organisations’ data.
This page describes the product as built. It is not a certification or a substitute for a supplier assessment; ask for the detail you need.