We build a security product, so we hold ourselves to the standard we ask of you.
Encryption in transit and at rest, least-privilege access, tenant isolation so accounts cannot see each other, and audit logging of sign-ins and changes.
Where we connect to your systems, we ask only for read-only access, and we never read the contents of your emails, files or messages.
If you believe you have found a security issue, please email [email protected]. We welcome good-faith reports, will acknowledge quickly, and will not take action against researchers who act responsibly.
Turn on two-factor authentication, use a strong unique password, and keep your recovery details up to date. The product will nudge you if any of these slip.