This policy is a draft, not yet approved by independent legal counsel.
The Service runs on edge runtime with edge-isolated compute. Each tenant data is logically separated through relational database, cache, and R2 isolation.
Authentication uses Cloudflare Access with WebAuthn for owner-tier accounts. Role-based access control enforces five admin layers.
All data in transit is encrypted via TLS 1.3. Data at rest is encrypted by Cloudflare infrastructure. Secrets are stored in Cloudflare Secrets Store.
Security vulnerabilities are tracked and remediated. Critical vulnerabilities are addressed within 72 hours. Dependency audits run in CI.
Security incidents are logged with signed receipts. Tenants are notified of confirmed data breaches per applicable law.
All surfaces enforce HSTS, Content-Security-Policy, X-Frame-Options, X-Content-Type-Options, and Permissions-Policy headers.