Tenant isolation
Multi-tenant architecture with row-level security in the database: each customer's data is separated and access-scoped at the data layer, not just the app.
Security & trust
Your contracts are sensitive and your buyers are discerning. SaaSoT is built security-first, with isolation, access control, and a complete audit trail by default.
Multi-tenant architecture with row-level security in the database: each customer's data is separated and access-scoped at the data layer, not just the app.
Multi-factor authentication (TOTP) and role-based access control, so people see only what their role allows. Anonymized views for board and investor users.
A complete audit log of changes, and manual adjustments that are explicitly noted and reversible. Every number can be traced to how it was produced.
AI commentary is generated from aggregates only. No individual customer names or PII are sent to the model, under a zero-data-retention posture.
Hosted on managed, reputable infrastructure (Supabase Postgres and Railway) with encryption in transit and at rest, and daily managed database backups.
This website runs no third-party analytics, ad, or tracking scripts and sets no cookies. Our own traffic measurement is cookieless and unlinkable across days — no IP addresses or user agents are ever stored. What we practice on our own site is the posture we bring to your data.
SOC 2 readiness is underway and third-party penetration testing is planned. We're happy to walk security teams through current controls.
Security and compliance posture evolves as we grow; this page reflects where things stand today. Reach out for current details or a security review.
Early access
Tell us where you're coming from and we'll be in touch. No spam, ever.