Security & App Security Guidelines
This page explains how Statisfy protects your data and the settings we recommend so your workspace and integrations stay secure.To report a security issue, email support@statisfy.com with “Security” in the subject line. See Reporting a security issue.
How Statisfy protects your data
Compliance
Statisfy is SOC 2 compliant. Compliance documentation is available in our Trust Center.Encryption
- In transit: all traffic uses HTTPS. HTTP requests are redirected to HTTPS, and connections require TLS 1.2 or higher with Google-managed certificates.
- At rest: data in Google Cloud is encrypted at rest by Google Cloud’s default encryption.
Tenant isolation
Each organization’s data lives in its own database schema, and every request is scoped to your organization through your signed-in session. This keeps each organization’s data separate from every other organization’s.Authentication and access control
- Sign-in is handled by Clerk. Every request is verified against a signed session token.
- Access is role-based: admin, builder, integration admin, member, and viewer roles control which features each user can see and change. See User management and roles.
- Single sign-on is available. See Setting up Okta SSO.
- Customer portals use passwordless sign-in (one-time codes and magic links). Codes are stored only as one-way hashes and are never logged.
AI and your data
- Statisfy uses foundational large language models (LLMs), such as Google Gemini (Vertex AI), Azure OpenAI, and Anthropic Claude, to power AI features.
- As stated in our Privacy Policy, Statisfy does not use customer data to train, fine-tune, or develop AI or machine-learning models.
- AI-generated answers can be inaccurate. Review them before you share or act on them.
File uploads and external connections
- Uploaded images are limited to allowed file types and 10 MB, and file names are sanitized.
- Custom MCP servers must use HTTPS, and addresses that point to private or internal networks are rejected.
Recommended app security practices
Follow these practices to keep your Statisfy workspace secure.Give users the least access they need
Give users the least access they need
Assign the viewer or member role by default, and reserve admin and integration admin for the people who manage settings and integrations. Review roles regularly in User management.
Remove access when people leave
Remove access when people leave
Remove departed users from your organization right away, and rotate any API keys or integration credentials they created or had access to.
Use SSO where you can
Use SSO where you can
Sign in through your identity provider so your company’s password, MFA, and offboarding policies apply to Statisfy. See Setting up Okta SSO.
Treat API keys like passwords
Treat API keys like passwords
- Create a separate key for each integration or script.
- Rotate keys regularly.
- Never commit keys to source control or paste them into chat or tickets.
- Revoke a key immediately if you think it was exposed.
Keep credentials in the Secret Store
Keep credentials in the Secret Store
Store API keys and passwords that automations need in the Secret Store rather than in prompts, notes, or workflow text.
Grant integrations the minimum permissions
Grant integrations the minimum permissions
When you connect an integration, choose only the permission sets you need. Disconnect integrations you no longer use so their access is revoked.
Connect only trusted MCP servers
Connect only trusted MCP servers
Add custom MCP servers only from providers you trust, and use credentials scoped to what Statisfy needs.
Review AI output before sharing it
Review AI output before sharing it
AI-generated summaries, drafts, and answers can be wrong. Check them before sending them to customers or using them for decisions.
Reporting a security issue
If you believe you’ve found a security vulnerability in Statisfy:- Email support@statisfy.com with “Security” in the subject line.
- Include a description of the issue, the steps to reproduce it, and the affected URL or feature.
- Don’t access or change other customers’ data, and don’t publicly disclose the issue until we’ve had a chance to fix it.