Security
Tenant work is isolated in Postgres. Session identity comes from Clerk. Official numbers are calculated by the engine, not invented by chat.
We do not claim SOC 2, ISO 27001, or a completed penetration test. A badge here would be false.
What is true today:
- Signed-in finance pages require a session. Nav hide is not authorization.
- Money-adjacent tables use tenant row isolation where migrations have landed. Historical close tables are not all FORCE RLS yet.
- We do not send pack amounts to third-party product analytics. First-party events store action names and ids.
- Ask may send prompts to OpenAI when that fallback is configured. Do not paste a full P&L into Ask as a default habit.
A signed DPA is owner-owned and is not published as a downloadable contract on this site.