Security
Built like the cards: to last under pressure.
Your workspace holds other people's details. Here's how we protect them — described plainly, without certifications we don't hold.
Workspace isolation
Every query is scoped to a workspace on the server, and access is checked against roles, permissions and business-level scoping before data is returned.
Encrypted secrets
Integration credentials and SSO client secrets are encrypted at rest with AES-256-GCM using a key derived for that purpose. They're never sent to the browser.
Strong password storage
Passwords are hashed with scrypt and a unique salt. Sign-in, sign-up and password reset are rate-limited, and sign-in timing doesn't reveal whether an account exists.
Sessions you can end
Sessions are stored server-side as hashed tokens in HTTP-only cookies. Changing your password signs out your other sessions.
Single sign-on and SCIM
Enterprise workspaces can require their identity provider. ID tokens are verified against the provider's published keys, and deprovisioning signs people out immediately.
Audit log
Role changes, exports, publishing, integrations, SSO changes and AI approvals are recorded in an append-only audit log.
Privacy for visitors
No tracking cookies on cards. Unique visits are estimated with a daily-rotating hash, and only country-level location is kept.
Safe uploads and links
Images are decoded and re-encoded (removing location metadata), SVG uploads are refused, and card links are checked against unsafe schemes.
Clean offboarding
Deactivating a member blocks their access immediately; their cards can be disabled and their records reassigned.
AI
AI with boundaries
AI features read only the workspace they're used in, only records the requesting person can see, and only what each request needs.
- Nothing AI-generated is sent, applied or published without a person approving it.
- Workspace questions use read-only lookups and cite the records they used.
- Administrators can turn AI off for the whole workspace, including the card concierge.
- Every AI request is metered and logged without storing prompt text in usage records.
Responsible disclosure
Found a vulnerability?
We appreciate reports from researchers and customers, and we won't pursue good-faith research that follows these guidelines.
- Report it through the contact form with “Security report” selected, including steps to reproduce.
- Only test against accounts and workspaces you own. Don’t access, change or delete other people’s data.
- Don’t run denial-of-service tests, spam, or social engineering against our staff or customers.
- Give us reasonable time to fix the issue before sharing details publicly.
Questions from your security team?
Enterprise customers can request our data processing agreement and sub-processor list, and discuss SSO and provisioning with us.