Security
How your data is protected.
Last updated 2026-04-22
In transit
TLS 1.3 from edge to API to gateways. Cert auto-renewal. HSTS preloaded.
At rest
Firestore encryption with Google-managed keys. Customer-managed keys (CMEK) available on Scale.
Access
Per-user Firestore rules: a workspace is readable only by its owner and explicit team members. Internal access requires SSO + MFA + just-in-time approval.
App Check
ReCAPTCHA v3 attestation on every Firestore / Auth / Storage call from the browser. Enable per project in Firebase Console.
Reporting an issue
Email security@sutrace.io. We'll acknowledge within 24 hours.