Trust

Security and Data Handling

Effective August 20, 2026 · Version 1.0-draft

Account and tenant controls

Customer data is scoped to an organization on every application query. Staff use role-gated endpoints with mandatory authenticator MFA. Sensitive staff actions and document access create append-only audit records.

Documents and infrastructure

Uploaded files use regenerated object names, private encrypted object storage, quarantine and malware scanning, strict type and size validation, and short-lived signed download links. Production services use encrypted transport, managed secrets, private data services, backups, monitoring, and least-privilege access.

Responsible reporting

Do not include sensitive customer data in an ordinary contact message. Report a suspected security issue through Contact with a request for the secure reporting channel. We investigate and coordinate remediation and notification under the incident-response plan.

Questions or requests: contact EzNRG.