Trust center

Security and trust posture

This page summarizes technical controls, data handling expectations, and operational transparency links.

Authentication and access

  • NextAuth based authentication
  • Workspace scoped role model (Owner/Admin/Member)
  • Route level authorization checks on API handlers

Operational safeguards

  • API rate limits for auth sensitive and data heavy routes
  • Approval events and audit timeline persistence
  • Plan based feature gating for premium workflow endpoints

Data handling

  • Invoice and workspace data stored in PostgreSQL
  • Attachment storage through Vercel Blob when configured
  • Export and deletion paths available from product workflows

Compliance and governance

Incaty does not hold a SOC 2, ISO 27001, or other third-party security certification today. The controls above are the current, actual state of the product. Security questionnaires and procurement review requests are welcome athello@incaty.com.

Live statusData policyBilling controls