Compliance ledger
Statuses reflect the current program state. Alignment to a framework is not certification. Evidence is available under NDA; see Document requests.
SecuritySecurity practices
Security practices
AdvisoriesSecurity advisories & CVEs
Security advisories & CVEs
Advisories affecting this product, plus our assessment of relevant third-party CVEs and external guidance. Ask the assistant about a specific CVE to have it check both this list and current public sources.
EcosystemSecurity incidents
Security incidents
Disclosure recordCoordinated disclosure record
Coordinated disclosure record
Coordinated vulnerability disclosureResponsible disclosureOpen to researchers
Responsible disclosureOpen to researchers
Good-faith security research is welcome. Reports are acknowledged within 2 business days, triaged and severity-scored, remediated on severity-based timelines (critical 7 days, high 30, medium 60, low 90), and disclosed in coordination with the reporter within 90 days by default. The full terms (scope, safe harbour, and what we commit to at each stage) are in the Coordinated Vulnerability Disclosure Policy.
Report a vulnerability
Safe harbor appliesSubmit a report below: it composes a structured email to the security team with a tracking reference, and nothing is transmitted from this page itself.
PrivacyData & privacy
Data & privacy
| Category | Handling |
|---|
ReliabilityAvailability & resilience
Availability & resilience
| Area | Commitment |
|---|
Third partiesSubprocessors
Subprocessors
Vendors that may process data in delivering the service. Each is reviewed before onboarding and annually.
The current list, with purpose, region and safeguards, is released under a non-disclosure agreement. Customers are given notice before a new subprocessor begins processing their data, as their agreement requires.
EvidenceDocuments & Policies
Documents & Policies
Public documents open directly. Private policies and assurance materials are available under NDA on request. Requests generate a pre-filled email and are logged locally in your browser only.
Policies
Assurance
Common questionsFAQ
FAQ
Reach the trust deskContact
Contact
For active incidents affecting your data, use the security contact and include "INCIDENT" in the subject line.