Controls that satisfy the people who ask hard questions
Single sign-on over SAML or OIDC, two-factor authentication, an audit log covering the actions that matter, session control, and the tooling to answer data subject requests properly.
Security in three steps.
Connect your identity provider
Configure SAML or OIDC so people sign in with your company account. Attributes coming back from the provider can decide which role someone receives.
Harden individual accounts
Turn on two-factor authentication using any authenticator app, with single-use backup codes for the day a phone goes missing.
Keep the record
Logins, permission changes, key revocations, domain changes, and data requests are written to the audit log, with personal data redacted as it is stored.
A closer look at security.
Single Sign-On
Sign in through your existing identity provider using SAML or OIDC, with roles assigned from the attributes it returns.
- SAML support
- OIDC support
- Attribute-based role assignment
- Provider secrets encrypted at rest
Two-Factor Authentication
Time-based codes from any standard authenticator app, backed by single-use recovery codes you can regenerate.
- TOTP with any authenticator app
- Single-use backup codes
- Codes regenerable at any time
Audit Log
A record of consequential actions — who changed a role, revoked a key, removed a domain, exported data — graded by severity and stripped of personal data.
- Authentication and session events
- Role and permission changes
- Key, domain and member changes
- Personal data redacted before storage
Data Subject Requests
Export a person's data, erase it, or correct it, with an audit trail for each — and a legal hold to block erasure where you are required to retain records.
- Data export
- Right to erasure
- Rectification of incorrect data
- Legal holds to prevent deletion
Session Control
Sessions expire and time out when idle, and can be ended everywhere or everywhere-but-here. Logins from unfamiliar devices are detected.
- Expiry and idle timeout
- Sign out of all sessions
- Sign out of other sessions only
- New-device detection
Where teams put it to work.
- ✓Meeting a security review before purchase
- ✓Enforcing company sign-in across a team
- ✓Answering a GDPR data request
- ✓Investigating who changed a permission
- ✓Removing access after someone leaves
- ✓Retaining records under a legal hold
The answers a security questionnaire asks for
Company sign-on, two-factor, a redacted audit trail, session control, and real data subject request handling — present rather than promised.
Common questions.
Related features.
Put security to work on your next campaign.
Everything is free while we're in beta. No credit card required.