01
Commitments
- Local-first desktop with team sync by choice
- No sale of personal data; no ad trackers for cross-site profiling
- Card data handled by Stripe (PCI); Etch does not store PANs
- Coordinated vulnerability disclosure via SECURITY.md
02
Baseline controls
- TLS in transit; Argon2 passwords; rotating refresh tokens
- Workspace secrets encrypted at rest (ChaCha20-Poly1305 AEAD)
- Tenant isolation checks on scoped APIs; rate limits on auth
- CI security scanning (CodeQL, cargo-audit, web-ci)
- Staging isolation; backup + deploy rollback procedures
03
Privacy surfaces
Privacy Policy · Subprocessors · Privacy request · DPA template · DMCA process
04
Certification roadmap (not yet certified)
- SOC 2 Type I readiness when enterprise demand warrants
- Independent penetration test residual
- ISO 27001 / 42001 evaluation residual
- Counsel sign-off to take Terms/Privacy in force
05
Contact
Security and privacy: contact@weareinformal.com

