Skip to content
Security

How we hold
your project data.

  • Isolation enforced below application code

    Each company’s data is separated at the infrastructure level — one tenant’s queries never reach another tenant’s rows.

  • Encrypted in transit and at rest

    All data is encrypted using TLS in transit and AES-256 at rest, with encryption keys managed separately from the application.

  • Primary data in India, on AWS Mumbai

    Project data resides in the Mumbai region. Any processing that occurs outside the primary region is disclosed in your contract.

  • Continuous backups with point-in-time recovery

    Backups run continuously — recovery targets any point in time, not just the last nightly snapshot.

  • Every change attributed

    The system records who changed what, when, and from where. The full audit trail is queryable and exportable.

  • Roles and scopes with least-privilege defaults

    Permissions are assigned by role and scoped to the EPS node, project, or WBS subtree they apply to. No user holds broader access than their work requires.

Certification posture

We have not completed SOC 2 or ISO 27001 certification. We provide full architecture documentation for your security team’s direct review and are transparent about our controls, our posture, and what we have not yet pursued.

Bring your security team
into the first call.