Certification status

We hold none of them.

This page exists because "we take security seriously" is what a vendor writes when the answer to this question is no. The answer here is no, and the useful version of that answer is which ones, what we do instead, and what it would take to change it.

Checked 11 August 2026. Every row below carries a real status rather than a badge, and none of them carries a target date, because we have not committed to one and inventing one here would be the first thing on this page that is not true.

No SOC 2. No ISO 27001. No external penetration test.

If any of those is a hard requirement in your procurement process, this is the paragraph that saves both of us a month. Say so in the first conversation and we will tell you plainly whether it is worth continuing.

Row by row

Each one, with what it would actually mean.

Standard or assuranceStatusWhat it would tell you that this site does not
SOC 2 Type IIthe usual first ask not held, not started That an independent auditor watched our controls operate over a period, rather than reading our description of them. That is a genuinely different claim from anything on this website.
SOC 2 Type Ipoint in time not held, not started That the controls were designed appropriately on one day. Cheaper and much weaker than Type II, and we would rather not hold the weak one and imply the strong one.
ISO 27001information security management not held, not started That there is a management system around security rather than a set of engineering decisions. At two people the honest position is that we have the second and not the first.
External penetration testnot a certification none commissioned That somebody outside this company tried to break it. Adversarial reviews have been run repeatedly against the code, and every one of them was run by us, which is a real limit on what they prove.
Bug bountycontinuous no programme Nothing yet. Reports are welcome at the address on the contact page and there is no reward, which we would rather say than let a security researcher discover after the work.
GDPRnot a certification at all a contractual position Nobody issues a GDPR certificate, and a vendor claiming one is telling you something about their marketing. Our position is set out in the data processing terms: you are the controller, we are the processor, and the sub-processor list is published.

Instead

What exists in place of an audit, and what it is worth.

Stated with the limit attached to each one, because a list of engineering practices presented as equivalent to an audit is exactly the substitution this page is meant to avoid.

  1. 01

    Isolation rules that are structural rather than procedural

    Thirteen of them, each written so that breaking it requires deleting code rather than forgetting a check, and each covered by tests that run offline and against a real database.

    The limit: our tests, testing our understanding of our own rules. See the security model.
  2. 02

    Repeated adversarial review of the isolation code

    Every change to the guard, the resolver, project routing, connection resolution or the caches gets a review whose job is to find the cross-client leak. Each round has found something the tests and the searches had not, including a defect inside a previous fix.

    The limit: internal. An external tester has different incentives and no attachment to the design.
  3. 03

    An access record you can read yourself

    The strongest thing here in practice: you do not have to trust our description of who reached what, because the trail is yours to read and export, refusals included.

    The limit: it tells you what happened, not that the controls around it were designed well.
  4. 04

    Published limits

    What it cannot do and this page are both written to be read by somebody looking for a reason to say no.

    The limit: candour is not assurance. It is easier to publish a weakness than to fix one.

What would change it

The honest trigger is a client who needs it.

How this would start

  • A client tells us it is required and we agree a timeline in the contract rather than on a website. That is the only trigger that has ever moved a certification at a company this size.
  • A penetration test is the first one worth buying, because it produces findings rather than a document, and the findings would go on the limits page.
  • This page changes the day any of that is true, with the date it changed.

What we will not do

  • No "SOC 2 in progress". It means an engagement letter has been signed and it reads as though the report exists. When one is signed, this page will say who is doing it and when the observation period starts.
  • No badge wall of cloud provider certifications. Microsoft's compliance is Microsoft's, it is real, and it says nothing about our software running on top of it.
  • No "audit-ready". The word means nothing and it is the tempting one.

Take this page to your reviewer first.

If it disqualifies us, it should do so in week one rather than in week six. If it does not, the review pack answers the rest.