Trusted infrastructure
Services run on major cloud providers and communicate over private networking, isolated from the public internet. Outbound requests are validated to prevent SSRF, and we're deliberate — and transparent — about the subprocessors that touch your data.
What this looks like in practice
- Services run on major cloud providers.
- Internal services communicate over private networking, isolated from the public internet.
- Outbound requests are validated to prevent SSRF.
- We're deliberate — and transparent — about the subprocessors that touch your data.
Why it matters
You shouldn't have to guess where your data lives or who can reach it. The internal surface isn't exposed to the internet, and the list of vendors that touch your data is short and disclosed.
- Major cloud providers
- Private networking
- SSRF protection
- Transparent subprocessors
Have a security question?
We're happy to walk through our practices in more detail, share documentation, or hear about a concern. A human reads every note.
This page describes our security posture at a high level for transparency; it is not a contractual commitment.