Skip to content

Security

Built like the cards: to last under pressure.

Your workspace holds other people's details. Here's how we protect them — described plainly, without certifications we don't hold.

Workspace isolation

Every query is scoped to a workspace on the server, and access is checked against roles, permissions and business-level scoping before data is returned.

Encrypted secrets

Integration credentials and SSO client secrets are encrypted at rest with AES-256-GCM using a key derived for that purpose. They're never sent to the browser.

Strong password storage

Passwords are hashed with scrypt and a unique salt. Sign-in, sign-up and password reset are rate-limited, and sign-in timing doesn't reveal whether an account exists.

Sessions you can end

Sessions are stored server-side as hashed tokens in HTTP-only cookies. Changing your password signs out your other sessions.

Single sign-on and SCIM

Enterprise workspaces can require their identity provider. ID tokens are verified against the provider's published keys, and deprovisioning signs people out immediately.

Audit log

Role changes, exports, publishing, integrations, SSO changes and AI approvals are recorded in an append-only audit log.

Privacy for visitors

No tracking cookies on cards. Unique visits are estimated with a daily-rotating hash, and only country-level location is kept.

Safe uploads and links

Images are decoded and re-encoded (removing location metadata), SVG uploads are refused, and card links are checked against unsafe schemes.

Clean offboarding

Deactivating a member blocks their access immediately; their cards can be disabled and their records reassigned.

AI

AI with boundaries

AI features read only the workspace they're used in, only records the requesting person can see, and only what each request needs.

  • Nothing AI-generated is sent, applied or published without a person approving it.
  • Workspace questions use read-only lookups and cite the records they used.
  • Administrators can turn AI off for the whole workspace, including the card concierge.
  • Every AI request is metered and logged without storing prompt text in usage records.

Responsible disclosure

Found a vulnerability?

We appreciate reports from researchers and customers, and we won't pursue good-faith research that follows these guidelines.

  • Report it through the contact form with “Security report” selected, including steps to reproduce.
  • Only test against accounts and workspaces you own. Don’t access, change or delete other people’s data.
  • Don’t run denial-of-service tests, spam, or social engineering against our staff or customers.
  • Give us reasonable time to fix the issue before sharing details publicly.

Questions from your security team?

Enterprise customers can request our data processing agreement and sub-processor list, and discuss SSO and provisioning with us.