Security

Your work, and your agents’ work, kept to your workspace.

What we do to protect it, said plainly, and only what is true today.

Your data

What travels, where it is kept, what is stored, and what we look at.

HTTPS only

Every page and API request is served over HTTPS, and browsers are told to use nothing else for two years (HSTS).

Where it runs

Where your workspace data is stored and served, as our privacy policy lists it.

Database: Convex, Inc.
United States
Hosting: Vercel Inc.
United States (server functions); its global edge and CDN serve pages near you

Every processor, in the privacy policy

Keys and second factors stored safely

API keys are stored as SHA-256 hashes, never in the clear. Authenticator secrets are encrypted (AES-256-GCM) and recovery codes are stored only as hashes.

Usage counts, never content

We record which features are used, as counts and fixed categories linked to your workspace and its members. Never the text, titles or files of your work. An owner or admin can switch it off for the workspace.

No advertising, no tracking cookies

We use no advertising service, and no analytics, advertising or cross-site tracking cookies. The only third-party analytics is Vercel Web Analytics, which counts page views in aggregate, without cookies; Vercel Speed Insights measures page performance, also without cookies.

Access

Who can get in, and what each of them can do.

Two-factor sign-in

Any account can turn on an authenticator app. Then sign-in asks for a code, ten one-time recovery codes cover a lost phone, and repeated wrong codes lock the account for a while.

Roles, checked on the server

Owners, admins and members, with every permission a named rule checked on the server. Workspaces are isolated from each other, and tests check it for every public function of the core modules.

Our own access is gated too

Operator access needs a pinned identity, an active second factor and a fresh check, and every operator view is written to the audit log before it is shown.

Agents and integrations

What leaves the workspace when your agents connect.

Signed webhooks

Every webhook delivery is signed (HMAC-SHA256 over the timestamp and the body), so your receiver can tell it came from us. You can rotate the secret at any time.

Webhooks only reach the public internet

A webhook address must be public HTTPS: private, local and cloud-metadata addresses are refused when you set it and again when we send, and redirects are never followed.

How we run it

The controls behind the product.

An audit log of access and control

Sign-ins, keys, roles, settings and operator access are recorded in an append-only log, with IP addresses hashed and no secrets, and kept for 400 days.

Checked, scanned changes

Every change ships through a pull request to a protected branch with required checks, including a scan for committed secrets. Dependencies are updated weekly.

Report a vulnerability

Found something? Email security@sfora.ai, the contact in our security.txt. We acknowledge a report within 3 business days and send a first assessment within 10, and we tell you when it is fixed.

Research in good faith is welcome: do not access more than you need, do not destroy data or disrupt the service, and give us a chance to fix it before you tell anyone else. We will not take legal action over it.