Skip to content

Security & Trust

Security built into the platform.

Isolation is a property of the database, not a setting on a page. This page describes each control, the privacy posture and the data flows from your browser.

  • Database-level tenant isolation
  • Per-app frame policy
  • Explicit permission prompts
  • Audit log for the actions auditors ask about
  • Privacy rules per jurisdiction pack
  • Health checks published

The controls

What is enforced, and where

Five controls built into the system.

  • Tenant isolation at the database layer

    Every record carries your organization's identity, and the database itself refuses to return another organization's rows - even if application code asked it to.

  • A security policy for every app

    Each app runs in its own frame under a policy built from what that app declared it needs. An app cannot quietly load scripts or send data to services it never declared.

  • Permission prompts you can see

    Sensitive capabilities are requested explicitly - what is being asked for, and by which app - and can be refused.

  • Every action recorded

    The Audit Log keeps who changed what, when and from where, for the actions your auditor asks about.

  • Privacy by jurisdiction

    Each jurisdiction pack carries its privacy rules. The Hong Kong pack is specified against PDPO and the PCPD's codes of practice for HR data: collect what the purpose needs, keep it for the period the law requires, and support access and correction.

Data flows

What the public site sends, and when

The marketing site runs no advertising trackers. Three flows start in your browser, all first-party; each is listed with the condition that allows it.

Browser-originated flows on this site
What leaves the browserWhat it carriesWhen it is sent
Usage analyticsNamed events with allow-listed properties only - page and action names, locale. Free text and sensitive keys are rejected before an event leaves the page.Only with your analytics consent
Performance vitalsLCP, INP and CLS measurements from the browser's own performance observer, so load experience is measured where it actually happens.Only with your analytics consent
Error reportsUncaught errors and unhandled rejections on public pages - the route and the error, so a broken page is repaired fast.Only when an error occurs

Your browser's network tab shows the same list. Workspace records never travel through these channels.

  • Service status

    Health checks for the public site and the API are published, including when something is degraded.

    Check live status
  • Procurement and security review

    Security questionnaires, DPA conversations and review calls go through one channel; a person answers, backed by the same controls this page states.

    Contact us

Want the walkthrough first?

The demo workspace is open, no account needed - and pricing is public, including what each plan does not include.