← Home

Security

This page is placeholder text describing the platform's defaults — review and confirm each statement for the product before launch.

Hosting and data location

The application runs on Cloudflare's global network; customer data is stored in a managed PostgreSQL database (Neon) and object storage (Cloudflare R2) in a single region. Backups use the database provider's point-in-time recovery.

Encryption

All traffic is encrypted in transit (TLS 1.2+, HSTS). Data is encrypted at rest by the storage providers. Passwords are hashed, never stored; API keys and personal access tokens are stored as hashes and shown once at creation.

Authentication and access

Email and password (checked against known breaches), optional sign-in with Google or Microsoft, and two-factor authentication (TOTP with backup codes). Workspace access is role-based; operations staff sign in with a verified address and two-factor authentication, and every staff action on customer data is recorded.

Tenant isolation

Every customer's data is scoped to their workspace at the application layer on every request; cross-workspace access is tested as part of our release process.

Audit trail

Security-relevant events — sign-ins, membership changes, credential creation and revocation, billing changes — are recorded in an append-only audit log available to workspace owners.

Sub-processors

Compliance

No third-party audit has been completed yet. Ask us about our current status and roadmap.

Reporting a vulnerability

Please report security issues privately to security@reminix.com— also published at /.well-known/security.txt. Include what you found, where, and how to reproduce it; we acknowledge reports within two business days and ask for reasonable time to fix before public disclosure.