Security
Your brand lives here. We treat it like it.
In place today
Tenant isolation.
Each client gets a private data partition. Enforced at three layers.
Tokens encrypted at rest.
Your connected-channel access tokens are encrypted with a dedicated key. The database never sees plaintext.
Auth on every action.
Identity is verified on every action. Every approval and publish resolves through a single, audited access path.
Append-only audit log.
Every approval, rework, publish, and credential change is logged. Entries are appended, never edited or deleted.
Strict CSP + HSTS.
No third-party script CDNs. Our inbox can't be embedded in someone else's frame.
Secrets never reach a commit.
Secret scanning runs on every push. Static analysis runs on every change. Dependency vulnerabilities are flagged as they appear.
Roadmap
- Q2 2026
- SOC 2 Type I — gap assessment.
- Q3 2026
- Single sign-on (SAML) for enterprise.
- Q4 2026
- SOC 2 Type I attestation issued.
- Q1 2027
- SOC 2 Type II observation window begins.
Harder question? Email security@map-app.net.
Sign up