Security & data
UK + EU data residency, daily backups, optional 2FA, immutable audit log.
Data location — primary VPS in Frankfurt; backups in EU object storage. Your data never leaves the EU.
Two-factor auth — Settings → Security → Enable 2FA. Scan the QR code with any authenticator app (Google, Authy, 1Password, Bitwarden). 10 backup codes generated at enrolment.
Audit log — every workspace change (role grants, billing events, member removals, etc.) is recorded immutably. Owners + admins can view it at Settings → Workspace → Audit log.
Backups — daily pg_dump cron, 30-day retention. Verified weekly by a restore-to-temp-DB job.
Client share links — when you share a project externally, only the read-only "client view" of that project is exposed. Margin, internal costs, and other-project data are never visible. Tokens are revocable any time.