Your team's data, treated like ours.
Encryption in the right places, EU data hosting in Frankfurt, sign-in with a magic link or passkey plus 2FA, and a security contact who actually replies. Plain-English answers below — including what we haven't built yet.
Data protection
Modern, boring cryptography in the right places. No clever schemes — just the things that auditors and your CISO expect.
Encryption at rest
Files in Cloudflare R2 are encrypted at rest (AES-256). Two-factor secrets are encrypted in the app with AES-256-GCM. Passwords are hashed with bcrypt.
Encryption in transit
TLS on every connection, with HSTS.
Daily backups
Daily database backups, kept in Frankfurt and rotated out within 90 days.
Audit log
Role changes, data exports and other admin actions go to an audit log kept 30 days on Free and 365 days on Pro. Owners and company admins can download up to 10,000 rows per export as CSV.
Identity & access
RBAC scoped per team today. SSO and SCIM are on our roadmap for teams that need them.
Roles that match your org
Owner / Admin / Lead / Member with per-team scope. A team lead in Helsinki can't see what Berlin is up to unless you say so.
SAML SSO + SCIM (roadmap)
Planned: wire up Okta, Google Workspace, Microsoft Entra ID, or any SAML-compliant IdP, with SCIM 2.0 to auto-deactivate seats when someone leaves your IdP. Not available yet — we'll announce it when it ships.
Two-factor authentication and passkeys
App-based TOTP 2FA with recovery codes is built in, and passkeys (YubiKey, Touch ID) are available for sign-in. Workspace-wide MFA enforcement is on our roadmap.
Sessions you can see
Every active session shows up in your account — device, IP address, last activity. One-click sign-out remotely.
Privacy
You own your team's data. We hold it under a clear DPA, in the EU, and we delete it when you say so.
Standard DPA
A standard EU-style Data Processing Agreement, published at /dpa — pre-filled and signed over email; we return a counter-signed copy. Signing it inside the app is not available yet.
EU data residency
Database and backups in Frankfurt, files in Western Europe — all inside the EU. Some processing runs in the US — the web app on Vercel, the AI provider, Stripe and Expo push — under SCCs.
Delete means delete
Deleting your account erases your personal data right away; it leaves backups within 90 days. Deleting asks for your password first — or a one-time emailed link, for accounts that never had one.
No selling, no ads, no training
Your data is never sold and never used to train models, and it's shared only with the sub-processors we list publicly — infrastructure (OVHcloud, Cloudflare, Vercel, Stripe) plus a handful of operational providers.
Where your data lives.
Your workspace data is stored in the EU today — the database in Frankfurt, files in Western Europe; the web app is served through Vercel. More regions are on the roadmap — we won't move your data without telling you.
Found a vulnerability?
We aim to reply within 2 business days and credit researchers who report responsibly. No legal sabre-rattling — just a respectful process.
Email security@altorbit.app