Security in the request path, not bolted on
We run our own WAF, DDoS shield, and rate-limiter in front of every request — and protect accounts with passkeys first. Security isn't a vendor we add; it's part of the platform.
How we protect you
Our own edge defence
WAF, DDoS absorption, and rate-limiting run on our capacity — there's no third party between your users and your app.
Passkeys first
WebAuthn passkeys are the default, with OAuth and TOTP as fallbacks. Phishing-resistant auth out of the box.
Encryption everywhere
TLS on every endpoint, encrypted private networking between services, and encryption at rest for your data.
Audit logs
Every privileged action is logged and exportable, so you always know who did what and when.
Isolation by design
V8 isolates and per-tenant boundaries keep workloads separated without the overhead of full VMs.
Responsible disclosure
Found something? Reach our security team directly — we respond fast and credit researchers.
Report a vulnerability
We take security seriously and respond quickly. Reach out any time.