Adrifact
ConsoleSign inGet started

SECURITY & COMPLIANCE

Built for the review your security team will run

We'd rather show you the controls than claim a badge we don't have yet. Here's exactly where we stand.

Controls in place today

Passkeys or a password

Sign in with a passkey (WebAuthn) or email and password. Single sign-on with your own provider is on the roadmap.

Encryption in transit

TLS on every endpoint. Tokens are stored as a hash, never as the secret; credentials are write-only — the API never hands one back.

One tenant, one boundary

Every record belongs to exactly one collection, and every request is answered inside the caller's. Checked continuously, from the outside.

Every change is signed

Who created a record and who last changed it is stamped on the record itself. Exporting that trail is on the roadmap.

EU data residency

Hosted in the EU. Single-tenant deployments on request.

No training on your data

Your inputs and artifacts are never used to train models.

Certification roadmap

honest status, not badges
FrameworkScopeStatus
SOC 2 Type IIPlatform, agents, storageIn progress
ISO 27001Information security managementPlanned
GDPR / DPAProcessing agreement, sub-processor listAvailable

Statuses above are placeholders for the dev team to confirm before launch.

Need our security package?

Architecture overview, sub-processors, and the DPA — sent same week.

Request the package