Enterprise-grade security, startup-friendly pricing
Security is not optional. Every webhook is signed, every connection is encrypted, and every action is logged.
TLS 1.3 Everywhere
All data encrypted in transit with TLS 1.3. No HTTP, no exceptions.
HMAC-SHA256 Signatures
Every webhook is signed with your secret. Verify authenticity with standard HMAC-SHA256.
2FA / TOTP
Two-factor authentication via authenticator apps. Protect your account beyond passwords.
SSO / SAML
Enterprise single sign-on. Integrate with Okta, Auth0, Google Workspace, and more.
IP Whitelisting
Restrict API access to specific IPs or CIDR ranges. Block unauthorized sources.
SSRF Protection
Built-in Server-Side Request Forgery protection. Block internal network access.
Argon2 Password Hashing
Industry-leading password hashing with Argon2id. No plaintext, no weak hashes.
Audit Logs
Track every action: who did what, when. Full audit trail for compliance.
EU Data Processing
Data processed in eu-central-1 (Frankfurt). GDPR compliant by design.
API Key Rotation
Rotate API keys without downtime. Old keys invalidated instantly.
Rate Limiting
Per-key rate limiting prevents abuse. Configurable per plan.
Webhook Secret Rotation
Rotate webhook secrets without breaking existing integrations. Dual-secret support.
Compliance & Standards
GDPR
CompliantEU data processing, data export/deletion, DPA available
SOC 2
ReadySecurity controls in place, Type 1 audit planned
CCPA
CompliantCalifornia Consumer Privacy Act compliance
KVKK
CompliantTurkish data protection law compliance
Standard Webhooks
CompliantOpen standard for webhook signatures and delivery
CloudEvents v1.0
SupportedCNCF standard for event data interoperability
Architecture security
Data at rest
- โขAll data encrypted in transit with TLS 1.3. No HTTP, no exceptions.
- โขNeon PostgreSQL with encrypted volumes
- โขUpstash Redis with TLS
- โขCloudflare R2
Data in transit
- โขTLS 1.3
- โขHSTS with preload
- โขCertificate pinning on API
- โขNo HTTP fallback
๐ Responsible Disclosure
Found a security vulnerability? We appreciate responsible disclosure. Please report with details.
We commit to acknowledging reports within 24 hours and providing a fix timeline within 72 hours.
Security questions?
Our team is happy to discuss your security requirements.