Encryption in transit & at rest
All traffic is served over TLS. Sensitive third-party credentials — Slack, Discord, and Microsoft Teams tokens, Google Chat webhook URLs — are encrypted at rest with AES-256-GCM.
Your standups contain real work context. We treat that data with the care it deserves — here's how.
All traffic is served over TLS. Sensitive third-party credentials — Slack, Discord, and Microsoft Teams tokens, Google Chat webhook URLs — are encrypted at rest with AES-256-GCM.
Every action is checked against organization and team roles — owner, admin, lead, member — so people only ever see their own workspace's data.
Short-lived signed access tokens with rotating, httpOnly refresh tokens. Password resets revoke every active session instantly.
Security headers, strict input validation, and per-route rate limiting protect the API against common abuse and injection vectors.
Export standups and analytics to branded PDF or raw CSV at any time. There's no lock-in — your data is yours to take with you.
Billing runs on Stripe. Card details are entered directly into Stripe's hosted fields — they never touch our servers (PCI SAQ A scope).
Found a vulnerability? We appreciate responsible disclosure — emailour team and we'll respond promptly.
We're happy to walk your team through how StandupSync handles data.