Security & Data
Specific controls, not security theatre.
We describe substantiated practices and facts still requiring production verification.
Data hosting and subprocessors
We publish provider and region details only after verifying live production projects.
Authentication and access
- Accounts use verified email and managed sessions.
- Workspace access is role-controlled.
- Failed sign-in protection stores an HMAC-derived key rather than raw addresses.
- Password reset links are stored hashed, expire after 30 minutes, and end every session on success.
- Invitations use hashed single-use tokens that lapse after seven days.
- Administrative access follows least-privilege principles.
The audit trail
Every change to roles, processes, and relationships is written to one append-only log as a typed event, so the workspace holds a record of what changed and who changed it. That log is not yet exposed as a customer-facing report.
Analytics and session recording
Coleoid uses explicitly defined, property-filtered analytics. Identified analytics and recording require consent.
Automatic exception capture is disabled and recording excludes request bodies and headers.
Data isolation
Organizational records carry an organization identifier and access is role-controlled; strict tenant isolation is not claimed pending audit.
Incidents and vulnerability reporting
Suspected incidents are investigated, contained, and documented. Report vulnerabilities to hello@coleoid.systems without credentials, tokens, or unnecessary personal data.
Certifications
Coleoid is not currently SOC 2 or ISO 27001 certified.