Legal & trust

Security

Designed for private workspaces, controlled publishing, and least-privilege access.

Last updated 16 September 2026

Private by default

Accounts use isolated workspaces with row-level access controls. One customer cannot read another customer's Brands or results.

Protected operations

Sensitive server operations verify the signed-in user and workspace membership before accessing data.

Public data boundaries

Public Business Passports use a curated server response rather than exposing private tables directly.

Responsible disclosure

If you believe you found a security issue, use the contact page and include enough detail for the team to reproduce it safely.