Security
This page is placeholder text describing the platform's defaults — review and confirm each statement for the product before launch.
Hosting and data location
The application runs on Cloudflare's global network; customer data is stored in a managed PostgreSQL database (Neon) and object storage (Cloudflare R2) in a single region. Backups use the database provider's point-in-time recovery.
Encryption
All traffic is encrypted in transit (TLS 1.2+, HSTS). Data is encrypted at rest by the storage providers. Passwords are hashed, never stored; API keys and personal access tokens are stored as hashes and shown once at creation.
Authentication and access
Email and password (checked against known breaches), optional sign-in with Google or Microsoft, and two-factor authentication (TOTP with backup codes). Workspace access is role-based; operations staff sign in with a verified address and two-factor authentication, and every staff action on customer data is recorded.
Tenant isolation
Every customer's data is scoped to their workspace at the application layer on every request; cross-workspace access is tested as part of our release process.
Audit trail
Security-relevant events — sign-ins, membership changes, credential creation and revocation, billing changes — are recorded in an append-only audit log available to workspace owners.
Sub-processors
- Cloudflare — hosting, networking, object storage, bot protection
- Neon — managed PostgreSQL
- Resend — transactional email
- Stripe — payments and invoicing
- Google, Microsoft — optional sign-in providers
Compliance
No third-party audit has been completed yet. Ask us about our current status and roadmap.
Reporting a vulnerability
Please report security issues privately to security@reminix.com— also published at /.well-known/security.txt. Include what you found, where, and how to reproduce it; we acknowledge reports within two business days and ask for reasonable time to fix before public disclosure.