Security Roadmap
What's live, what's next, and what triggers it
We publish trigger-tied milestones, not calendar dates. A missed date is a credibility hit; a trigger that hasn't fired yet is honest scope.
Live today
- Hash-chained audit trail — SHA-256 chain shared with RegAlign®, auditor-verifiable without an account.
- Row-level tenant isolation enforced by RLS + SECURITY DEFINER helpers.
- 2FA available for all roles; mandatory for elevated roles once first paying tenant signs.
- Continuous code scanning: SAST, secrets, IaC, dependency. Code only — no customer data.
- EU data residency — primary database and file storage in EU (Ireland).
- Encryption: TLS 1.2+ in transit; AES-256 at rest.
- Published Vulnerability Disclosure Policy + /.well-known/security.txt.
Trigger-tied next steps
- DEV_OPEN cutover (mandatory MFA, tenant scoping enforced, dev-only routes gated)Trigger: Before any real customer data lands. Hard blocker for first paid pilot.
- Independent penetration testTrigger: First paid pilot signed, or first enterprise procurement requirement.
- Cloud security posture management (CSPM) selectedTrigger: Within 90 days of first paying customer onboarding, or first enterprise procurement requirement.
- Documented backup-restore drill from production snapshotTrigger: Within 60 days of first paying customer onboarding.
- SOC 2 Type I — observation window openedTrigger: Within 6 months of Series A close, or before second enterprise customer onboarding.
- SOC 2 Type IITrigger: 12 months after Type I report issued.
- ISO 27001 ISMS initiatedTrigger: Once headcount supports a dedicated security function (≥1 FTE).
- Per-tenant session-timeout policy and IP allow-listTrigger: Before first enterprise customer onboarding, or on request.
See also: Trust Centre, Vulnerability Disclosure Policy, AI Use Disclosure, Known Limitations.