Security Roadmap

What's live, what's next, and what triggers it

We publish trigger-tied milestones, not calendar dates. A missed date is a credibility hit; a trigger that hasn't fired yet is honest scope.

Live today

  • Hash-chained audit trail — SHA-256 chain shared with RegAlign®, auditor-verifiable without an account.
  • Row-level tenant isolation enforced by RLS + SECURITY DEFINER helpers.
  • 2FA available for all roles; mandatory for elevated roles once first paying tenant signs.
  • Continuous code scanning: SAST, secrets, IaC, dependency. Code only — no customer data.
  • EU data residency — primary database and file storage in EU (Ireland).
  • Encryption: TLS 1.2+ in transit; AES-256 at rest.
  • Published Vulnerability Disclosure Policy + /.well-known/security.txt.

Trigger-tied next steps

  • DEV_OPEN cutover (mandatory MFA, tenant scoping enforced, dev-only routes gated)
    Trigger: Before any real customer data lands. Hard blocker for first paid pilot.
  • Independent penetration test
    Trigger: First paid pilot signed, or first enterprise procurement requirement.
  • Cloud security posture management (CSPM) selected
    Trigger: Within 90 days of first paying customer onboarding, or first enterprise procurement requirement.
  • Documented backup-restore drill from production snapshot
    Trigger: Within 60 days of first paying customer onboarding.
  • SOC 2 Type I — observation window opened
    Trigger: Within 6 months of Series A close, or before second enterprise customer onboarding.
  • SOC 2 Type II
    Trigger: 12 months after Type I report issued.
  • ISO 27001 ISMS initiated
    Trigger: Once headcount supports a dedicated security function (≥1 FTE).
  • Per-tenant session-timeout policy and IP allow-list
    Trigger: Before first enterprise customer onboarding, or on request.

See also: Trust Centre, Vulnerability Disclosure Policy, AI Use Disclosure, Known Limitations.