Security
Evidence deserves controls.
Last updated September 1, 2026
Application security
- Every customer record carries a workspace identifier.
- Database policies and scoped queries enforce tenant boundaries.
- Project keys are scoped, revocable, hashed, and displayed once.
- State transitions create append-only provenance events.
Data protection
- TLS protects data in transit.
- Managed infrastructure encryption protects data at rest.
- Screenshot access requires authorization and expires.
- Exports and deletion require recent authentication.
Operational controls
- Production configuration fails closed.
- Dependency scanning blocks unresolved critical findings.
- Backups, restoration, and incident response are tested before general availability.
- Customer data never enters public logs or client bundles.
Report a vulnerability
Email security@phronetos.com. Include reproduction steps and impact. Do not access data that is not yours. We will acknowledge a valid report within two business days.
Procurement
Design partners can request the data processing addendum, subprocessor list, architecture review, and current control evidence.