Built to keep your data yours.
Organization isolation by default. Encryption everywhere. Full audit trail. Bring your own model keys so the only place your data lives is your infrastructure.

Four foundations.
Data isolation
Every resource is org-scoped at the database. One org cannot see another's data — enforced by repository-level filters, not application logic.
Encryption
API keys encrypted at rest with AES-256-GCM. TLS 1.3 in transit.
Access control
Role-based access at the global and organization level. Better Auth-backed sessions with CSRF protection. SAML/OIDC SSO and SCIM provisioning for enterprise IdPs.
Audit & monitoring
Admin and resource actions captured in an append-only audit log. Exportable per organization as CSV or JSON.
Where we are. Where we're going.
Current
- • Per-organization data isolation enforced at the database level
- • Encrypted API keys (AES-256-GCM)
- • Audit logging on admin and resource actions
- • RBAC at global and organization scope
- • SAML/OIDC SSO and SCIM 2.0 provisioning
- • Better Auth-backed sessions with CSRF protection
- • Self-hosting on Docker, Kubernetes, or bare metal
On the roadmap
- • SOC 2 Type II audit
- • IP allowlisting for admin access
- • Audit log retention policies
- • Force-logout-all-sessions admin action
Found something? Tell us.
We treat security reports with priority. Email us with reproduction steps and we'll respond within one business day.
Contact security