Security

How your data is protected.

Last updated 2026-04-22

In transit

TLS 1.3 from edge to API to gateways. Cert auto-renewal. HSTS preloaded.

At rest

Firestore encryption with Google-managed keys. Customer-managed keys (CMEK) available on Scale.

Access

Per-user Firestore rules: a workspace is readable only by its owner and explicit team members. Internal access requires SSO + MFA + just-in-time approval.

App Check

ReCAPTCHA v3 attestation on every Firestore / Auth / Storage call from the browser. Enable per project in Firebase Console.

Reporting an issue

Email security@sutrace.io. We'll acknowledge within 24 hours.