Security

Read first, answered first.

We run our own products in production and treat client systems with the same care. Here is how we work, and how to reach us if you find a problem.

01 — How we work

Our practices.

Least privilege
Production access is limited to the people who operate a system, reviewed when roles change.
Encryption
Data is encrypted in transit everywhere, and at rest on the platforms that store it.
Separation
Client environments, product environments and internal tooling are kept apart. Client code never trains or feeds our products.
Dependencies
We keep dependencies current and monitor advisories for everything we run in production.
Backups
Databases we operate are backed up automatically, and restores are tested rather than assumed.
People
Small team, hardware-key two-factor on the accounts that matter, and no shared credentials.

02 — Disclosure

Found a vulnerability?

Report it to security@phronesisailab.com. Include what you found, where, and how to reproduce it. We acknowledge reports within 48 hours, keep you informed while we fix, and credit researchers who want credit. Please give us reasonable time to fix before disclosing publicly, and do not access data that is not yours.