> ## Documentation Index
> Fetch the complete documentation index at: https://help.statisfy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Security & App Security Guidelines

> How Statisfy protects your data, and the practices we recommend for keeping your workspace and integrations secure.

# Security & App Security Guidelines

This page explains how Statisfy protects your data and the settings we recommend so your workspace and integrations stay secure.

<Note>
  To report a security issue, email **[support@statisfy.com](mailto:support@statisfy.com)** with "Security" in the subject line. See [Reporting a security issue](#reporting-a-security-issue).
</Note>

## How Statisfy protects your data

### Compliance

Statisfy is **SOC 2 compliant**. Compliance documentation is available in our [Trust Center](https://trustcenter.statisfy.com/).

### Encryption

* **In transit:** all traffic uses HTTPS. HTTP requests are redirected to HTTPS, and connections require **TLS 1.2 or higher** with Google-managed certificates.
* **At rest:** data in Google Cloud is encrypted at rest by Google Cloud's default encryption.

### Tenant isolation

Each organization's data lives in its **own database schema**, and every request is scoped to your organization through your signed-in session. This keeps each organization's data separate from every other organization's.

### Authentication and access control

* Sign-in is handled by Clerk. Every request is verified against a signed session token.
* Access is **role-based**: admin, builder, integration admin, member, and viewer roles control which features each user can see and change. See [User management and roles](/admin/user_management_and_roles_guide).
* Single sign-on is available. See [Setting up Okta SSO](/integrations/setting_up_okta_sso_with_statisfy).
* Customer portals use **passwordless sign-in** (one-time codes and magic links). Codes are stored only as one-way hashes and are never logged.

### AI and your data

* Statisfy uses foundational large language models (LLMs), such as Google Gemini (Vertex AI), Azure OpenAI, and Anthropic Claude, to power AI features.
* As stated in our [Privacy Policy](https://www.statisfy.com/privacy-policy), Statisfy does **not** use customer data to train, fine-tune, or develop AI or machine-learning models.
* AI-generated answers can be inaccurate. Review them before you share or act on them.

### File uploads and external connections

* Uploaded images are limited to allowed file types and **10 MB**, and file names are sanitized.
* Custom MCP servers must use **HTTPS**, and addresses that point to private or internal networks are rejected.

## Recommended app security practices

Follow these practices to keep your Statisfy workspace secure.

<AccordionGroup>
  <Accordion title="Give users the least access they need">
    Assign the **viewer** or **member** role by default, and reserve **admin** and **integration admin** for the people who manage settings and integrations. Review roles regularly in [User management](/admin/user_management_and_roles_guide).
  </Accordion>

  <Accordion title="Remove access when people leave">
    Remove departed users from your organization right away, and rotate any API keys or integration credentials they created or had access to.
  </Accordion>

  <Accordion title="Use SSO where you can">
    Sign in through your identity provider so your company's password, MFA, and offboarding policies apply to Statisfy. See [Setting up Okta SSO](/integrations/setting_up_okta_sso_with_statisfy).
  </Accordion>

  <Accordion title="Treat API keys like passwords">
    * Create a separate key for each integration or script.
    * Rotate keys regularly.
    * Never commit keys to source control or paste them into chat or tickets.
    * Revoke a key immediately if you think it was exposed.
  </Accordion>

  <Accordion title="Keep credentials in the Secret Store">
    Store API keys and passwords that automations need in the [Secret Store](/admin/secret_store) rather than in prompts, notes, or workflow text.
  </Accordion>

  <Accordion title="Grant integrations the minimum permissions">
    When you connect an integration, choose only the permission sets you need. Disconnect integrations you no longer use so their access is revoked.
  </Accordion>

  <Accordion title="Connect only trusted MCP servers">
    Add custom MCP servers only from providers you trust, and use credentials scoped to what Statisfy needs.
  </Accordion>

  <Accordion title="Review AI output before sharing it">
    AI-generated summaries, drafts, and answers can be wrong. Check them before sending them to customers or using them for decisions.
  </Accordion>
</AccordionGroup>

## Reporting a security issue

If you believe you've found a security vulnerability in Statisfy:

1. Email **[support@statisfy.com](mailto:support@statisfy.com)** with "Security" in the subject line.
2. Include a description of the issue, the steps to reproduce it, and the affected URL or feature.
3. Don't access or change other customers' data, and don't publicly disclose the issue until we've had a chance to fix it.

We aim to respond within **3 business days**.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.