Skip to content
New: simulate any flow against real records before it goes live. See what's new

Security & trust

Your data, treated like it's ours

Enterprise controls as standard: identity integration, enforced roles, field-level auditability and Australian data residency.

Identity

Enterprise SSO, SCIM directory sync, MFA with recovery codes and active session management.

Access control

Owner, Admin, Member and Viewer roles enforced server-side on every route, plus per-workspace member policies and record visibility.

Auditability

Every mutation logged with the actor and field-level diffs — records, settings, members and email configuration alike.

The specifics

  • Hosted on AWS in Sydney, Australia (ap-southeast-2)
  • PostgreSQL (Amazon RDS) with encryption at rest
  • TLS for all traffic; Cloudflare at the network edge
  • Credentials hashed with bcrypt; sessions expire after 7 days and 8 hours idle
  • MFA with recovery codes; enterprise SSO; SCIM provisioning
  • Role-based access enforced in a single, audited access layer
  • Per-record visibility (workspace vs private) controls
  • Complete audit log with field-level diffs, sealed hourly and verifiable on demand
  • Automated data deletion 30 days after you schedule it, with a cancellable window
  • Email webhooks signature-verified; inbound HMAC-signed
  • Automation HTTP actions SSRF-guarded with private ranges blocked
  • AI features can be disabled per workspace, enforced in the application
  • Dependency, static-analysis and container scanning on every change
  • CSV export of your records at any time

Frequently asked questions

On AWS in the Sydney region (ap-southeast-2). Database storage is encrypted at rest and traffic is encrypted in transit.

Yes — enterprise single sign-on and SCIM directory sync are available, alongside MFA with recovery codes for credential accounts.

Yes. Records, lists and reports export as CSV at any time. When you schedule deletion, your data stays fully available for 30 days — and you can cancel during that window — after which it is permanently erased automatically. We keep only the audit record showing the deletion happened.

Only when you use an AI feature, and only the content that feature needs. Anthropic is the model provider; Customer Data is never used to train models. If your policy doesn't allow a third-party model provider, an admin can turn AI off for your whole workspace — it's enforced in the application, not just hidden in the interface.

Not yet — we hold neither certification today, and we'd rather say so than imply otherwise. The underlying controls are documented and we're happy to walk your team through them or complete your security questionnaire.

Report to [email protected] — see solstral.com/.well-known/security.txt. Reports go straight to the engineering team and are acknowledged within one business day. Customers affected by a personal data breach are notified within 72 hours.

Team reviewing work together in a meeting

People, not just controls

Security questions get engineering answers

Send your security questionnaire or book a call — the people who built the authentication, audit and isolation layers are the ones who answer.

Need a security review?

We'll walk your team through the architecture and controls.