Security & trust, documented honestly
GrowthOS is built on real, verifiable controls — role-based access enforced server-side, sensitive data encrypted at rest under independent keys, tamper-evident audit logs, and continuous health monitoring. Every claim on this page is backed by working code, not a marketing checklist, and we say so plainly where something isn't in place yet.
How a request actually flows through this system
A real, current picture of the request path — deliberately described in generic infrastructure terms, not a diagram of aspirational infrastructure.
Your team and customers connect over HTTPS from any standard web browser.
Incoming traffic is decrypted and routed by a reverse proxy in front of the application.
The application runs in an isolated container, as a non-root user, with resource limits.
Application data is persisted in PostgreSQL and never exposed to the public internet.
Redis handles caching and rate limiting, reachable only from inside the internal network.
Sensitive data and credentials are encrypted at rest, each domain under its own independent key.
A nightly job produces a checksummed, verified database backup automatically.
Database, cache, storage, and job-queue health are checked continuously and recorded over time.
Sensitive actions are recorded in a tamper-evident, hash-chained audit trail.
Critical failures trigger automated alerts to our operations channel the moment they're detected.
The principles behind how we build
Real engineering practices this codebase follows — expand a card for the detail behind the claim.
Where we stand, framework by framework
A real architectural-readiness snapshot — tap a framework for the full, unedited detail, including what it doesn't mean.
Third-party audited certifications
Independent audits and partnerships, tracked separately from our own built-in security controls.
Third-party certifications
Coming soonWe don't hold any third-party audited certifications or cloud-provider partnerships yet. This is separate from our own security features — see the Security & Compliance section for the controls already built into the platform.
This isn't built yet — check back in a future release.
How data is protected at rest and in transit
Every claim below is backed by working code in this platform.
Sensitive data — agent memory, integration tokens, secrets, webhook signing keys, 2FA secrets — encrypted at rest, each under its own independent key.
Production traffic is served over HTTPS.
Passwords are hashed with bcrypt/Argon2 — never stored in plain text, never reversible.
A dedicated, encrypted secrets vault stores credentials — values are never selectable through the listing UI, only metadata.
Integration OAuth tokens and API credentials are encrypted before being stored.
Who can do what, and how it's enforced
Every claim below is backed by working code in this platform.
Ten distinct roles with server-enforced, tenant-isolated permissions.
Authenticator-app-based 2FA, with the secret encrypted at rest.
Sessions can be revoked server-side at any time — a real 'log out everywhere,' not just clearing a cookie.
Sensitive actions are recorded in a tamper-evident, cryptographically chained audit trail.
API access uses bearer tokens that are hashed before storage — the raw key is never stored or retrievable again after creation.
Credentials are encrypted at rest in a dedicated vault, never exposed through the listing UI.
A hardened, isolated deployment — not just a claim
Every item below is backed by working infrastructure in this deployment — tap a card for detail.
Watched continuously, not checked occasionally
From detection to public disclosure — here's what actually happens when something breaks.
- 1
Continuous Health Checks
Database, cache, storage, and queue health are checked automatically and recorded over time.
- 2
Automated Alerting
Critical alerts are dispatched automatically to our operations channel the moment they're detected.
- 3
Incident Tracking
Real incidents are logged, tracked to resolution, and reviewed — not handled ad hoc.
- 4
Transparent Status
Real historical uptime is publicly visible on our status page — not a marketing claim.
Real historical uptime, publicly visible
Live health checks and incident history — not a marketing claim.
Your data, under your control
Real, working privacy controls built into the product — not just a policy document.
Download a complete export of your own data as JSON, on demand — no request ticket or waiting period required.
Deleting or anonymizing your account is a genuinely destructive-action-protected flow — you must type a confirmation phrase and re-enter your password before anything is removed.
Analytics cookies are opt-in and off by default. We only set them after you explicitly consent, and you can withdraw that consent at any time.
Manage your data
Export or delete your data directly from your account settings.
Privacy requests
Have a question about how we handle your data? Reach our support team directly.
GDPR-aligned data rights, for real
Consent, export, and deletion are backed by working code — not just a policy statement.
Export my data
Download a full copy of your data as JSON from your account.
Delete my data
Delete or anonymize your account, protected by a confirmation phrase and password re-check.
Documentation request
Need a copy of our Data Processing Agreement or other GDPR documentation? Reach out and we'll send it over.
Where your data lives
A straightforward, honest statement about our current hosting footprint.
Single-region, cloud-hosted deployment today.
All application data is currently hosted in a single cloud region. Customer-selectable region and multi-region failover are on our roadmap but not available yet — we won't claim otherwise until they're real.
Resources we're still preparing
These aren't ready yet — we'd rather tell you honestly than fake it.
Security Whitepaper
Coming soonA downloadable architecture and controls overview is in progress.
This isn't built yet — check back in a future release.
Penetration Testing
Coming soonNo third-party penetration test has been conducted yet — real results will be published here once one has.
This isn't built yet — check back in a future release.
Responsible Disclosure Program
Coming soonA formal vulnerability-disclosure policy and security contact are in progress.
This isn't built yet — check back in a future release.
Enterprise security documents
Some documents are available to download right now; others are available on request while we finish preparing them.
Put your growth engine on autopilot
Start qualifying, engaging, and converting pipeline with AI agents today. No credit card required, and your first workflow can be live in under fifteen minutes.