All data is encrypted in transit and at rest, access is scoped by workspace roles, and every change is written to an immutable audit log. Independent penetration tests run twice a year, and the reports are available to every customer on request.