Trust
Dedicated database per tenant, dedicated encryption key, and an incident policy we publish against.
Overview
Every tenant runs in a dedicated database with its own encryption key, held in a hardware security module. There is no shared schema and no cross-tenant query path. Key rotation is quarterly and can be triggered by you at any time.
Access to production requires hardware-token authentication and is logged with the ticket that justified it. We publish an incident report within five working days of any incident affecting your tenant, whether or not the cause was ours.
Next step
Your first call is with an engineer, not a sales-development representative.