Security
You're trusting us with bills, policies, and family documents. Here is exactly how that trust is protected — every claim on this page describes shipped, tested behavior.
Workspace isolation, enforced by the database
Every record belongs to your workspace, and isolation is enforced with row-level security on every table — not just application code. Members of one workspace cannot read another's data, and we verify this continuously with a live isolation test suite.
Two-factor authentication
Accounts support authenticator-app 2FA, and sensitive actions — like removing a factor or changing your password — require re-confirming your password even inside a logged-in session.
Private document storage
Uploaded documents live in private storage with no public URLs. Files are served only through short-lived signed links (about a minute) to authorized members of your workspace, and every download is recorded.
AI that asks first
Document extraction proposes fields — nothing is saved to your records until you review and approve it. AI features are also budget-capped per workspace.
A full audit trail
Creates, edits, deletions, downloads, sign-ins, and membership changes are written to an append-only audit log your workspace admins can rely on.
Encrypted connections and credentials
Everything runs over HTTPS with a strict content-security policy. Credentials for connected services (like Google) are encrypted at rest with a dedicated key that never leaves the server.
Found a vulnerability? Report it privately to security@chaosops.ai (see also security.txt). Your data, your exit: privacy policy and full workspace export are built in.