SECURITY

Controls that satisfy the people who ask hard questions

Single sign-on over SAML or OIDC, two-factor authentication, an audit log covering the actions that matter, session control, and the tooling to answer data subject requests properly.

SSO with SAML and OIDC Two-factor with backup codes Audit log with PII redaction Export, erasure and correction
security settings
SSOSAML · OIDC
Two-factorTOTP + backup codes
Audit logPII redacted
GDPRexport · erase · correct
AES-256-GCM
SAML
& OIDC sign-on
TOTP
two-factor
Audited
sensitive actions
GDPR
request tooling
HOW IT WORKS

Security in three steps.

01

Connect your identity provider

Configure SAML or OIDC so people sign in with your company account. Attributes coming back from the provider can decide which role someone receives.

02

Harden individual accounts

Turn on two-factor authentication using any authenticator app, with single-use backup codes for the day a phone goes missing.

03

Keep the record

Logins, permission changes, key revocations, domain changes, and data requests are written to the audit log, with personal data redacted as it is stored.

CAPABILITIES

A closer look at security.

Single Sign-On

Sign in through your existing identity provider using SAML or OIDC, with roles assigned from the attributes it returns.

  • SAML support
  • OIDC support
  • Attribute-based role assignment
  • Provider secrets encrypted at rest

Two-Factor Authentication

Time-based codes from any standard authenticator app, backed by single-use recovery codes you can regenerate.

  • TOTP with any authenticator app
  • Single-use backup codes
  • Codes regenerable at any time

Audit Log

A record of consequential actions — who changed a role, revoked a key, removed a domain, exported data — graded by severity and stripped of personal data.

  • Authentication and session events
  • Role and permission changes
  • Key, domain and member changes
  • Personal data redacted before storage

Data Subject Requests

Export a person's data, erase it, or correct it, with an audit trail for each — and a legal hold to block erasure where you are required to retain records.

  • Data export
  • Right to erasure
  • Rectification of incorrect data
  • Legal holds to prevent deletion

Session Control

Sessions expire and time out when idle, and can be ended everywhere or everywhere-but-here. Logins from unfamiliar devices are detected.

  • Expiry and idle timeout
  • Sign out of all sessions
  • Sign out of other sessions only
  • New-device detection
USE CASES

Where teams put it to work.

  • Meeting a security review before purchase
  • Enforcing company sign-in across a team
  • Answering a GDPR data request
  • Investigating who changed a permission
  • Removing access after someone leaves
  • Retaining records under a legal hold

The answers a security questionnaire asks for

Company sign-on, two-factor, a redacted audit trail, session control, and real data subject request handling — present rather than promised.

SSO
SAML and OIDC
AES-256
for secrets at rest
FAQ

Common questions.

KEEP EXPLORING

Related features.

Put security to work on your next campaign.

Everything is free while we're in beta. No credit card required.