MAP

Security

Your brand lives here. We treat it like it.

In place today

Tenant isolation.

Each client gets a private data partition. Enforced at three layers.

Tokens encrypted at rest.

Your connected-channel access tokens are encrypted with a dedicated key. The database never sees plaintext.

Auth on every action.

Identity is verified on every action. Every approval and publish resolves through a single, audited access path.

Append-only audit log.

Every approval, rework, publish, and credential change is logged. Entries are appended, never edited or deleted.

Strict CSP + HSTS.

No third-party script CDNs. Our inbox can't be embedded in someone else's frame.

Secrets never reach a commit.

Secret scanning runs on every push. Static analysis runs on every change. Dependency vulnerabilities are flagged as they appear.

Roadmap

Q2 2026
SOC 2 Type I — gap assessment.
Q3 2026
Single sign-on (SAML) for enterprise.
Q4 2026
SOC 2 Type I attestation issued.
Q1 2027
SOC 2 Type II observation window begins.

Harder question? Email security@map-app.net.

Sign up