Trust & Security
8200.dev is built to meet enterprise security requirements. This page describes how we protect your data, what we can and cannot access, and how we operate. We state our posture plainly — and we never claim a certification we do not hold.
1. Security Architecture
Encryption at rest
All sensitive data, including connector credentials and identity-provider certificates, is encrypted at rest with AES-256-GCM.
Encryption in transit
All traffic is served over TLS 1.3 (HTTPS), with HSTS enforced so browsers refuse to connect insecurely.
Authentication & MFA
Sign in with Google, or with an email and password — at least 12 characters, stored only as salted scrypt hashes, with rate-limited sign-in attempts. Two-factor authentication (TOTP plus backup codes) is available to everyone and can be required org-wide; Enterprise adds SAML single sign-on (Okta, Azure AD, Google Workspace, OneLogin) with just-in-time provisioning and assertion replay protection.
Role-based access control
Built-in Owner, Admin, and Viewer roles plus fine-grained custom roles let you grant least-privilege access. Permissions are enforced on every request.
Session & network controls
Configurable session maximum-duration and idle-timeout policies, plus IP allowlisting that restricts access to ranges you trust (Enterprise).
Edge protection
Cloudflare provides a Web Application Firewall and DDoS protection in front of the application, with security headers (CSP, HSTS, frame-deny) on every response.
2. Data Handling
Monitoring is read-only. The platform connects with the narrowest scopes that let it assess your posture, it never needs the contents of your files, and it changes nothing in your sources unless you turn on auto-remediation.
Read-only monitoring
Connectors monitor through read-only scopes. For Google Workspace, the scan runs on drive.metadata.readonly — it can read sharing metadata, not file contents. Write access exists only for auto-remediation: off by default, granted separately per connector, and limited to revoking or reducing access.
Metadata and findings only
We store permission metadata, the access graph, and the findings we derive from it. We do not store, index, or transmit the contents of your documents.
Configurable retention
Operational data follows your retention policy — for example up to 24 months of audit history and a 90-day window for transient data — with a safety floor so nothing is purged accidentally.
Self-serve export & deletion
Owners can export their organization’s data and request account deletion themselves. Deletion runs on a grace window and then removes the data.
3. Compliance
We map our controls and the evidence the product generates to the major frameworks. These are mappings to help your own audit — 8200.dev is not certified against these standards, and we will never claim otherwise.
Framework mapping
Controls and product evidence are mapped to SOC 2, ISO 27001, GDPR, HIPAA, and NIST CSF 2.0. The in-app compliance dashboard tracks all five side by side with gap analysis and an exportable evidence package.
Google API Limited Use
The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Workspace data is used only to provide and improve the security features you enable — we never use it to develop, improve, or train generalized AI or machine-learning models, and we never transfer it to third-party AI or ML tools or services for training purposes.
Google OAuth verification
Google approved 8200.dev’s OAuth verification on 2026-08-23 for the three scopes it requests: drive.metadata.readonly for the scan, and admin.directory.user.readonly and admin.directory.user.security for the optional third-party-app audit. Any new scope — including the write scope auto-remediation would need on Google Workspace — requires a new verification before we use it.
4. AI Agent Accountability
The 2026 liability shift holds the company deploying AI accountable for what its agents do. 8200.dev produces the evidence that you governed that access. This supports your compliance posture; it is not legal advice and does not guarantee any outcome.
Complete agent inventory
Agent Guard keeps a live inventory of every AI agent and service account that can reach your data, plus the third-party OAuth grants behind shadow AI — you cannot govern what you cannot see.
Immutable access record
Every access decision and change is recorded in an exportable audit trail (CSV / JSON / CEF / SIEM), so you can reconstruct what an AI agent could reach, and when.
Demonstrable governance
Prevention rules, access enforcement, and a documented risk timeline show active control and response — the evidence behind a defensible AI-governance program.
5. Operational Security
Continuous health checks
Automated health checks run every five minutes across the platform, database, and connectors, opening an incident automatically when something degrades.
Public status page
A public status page publishes uptime history and incident updates so you always know the current state.
Automated testing
The codebase is covered by more than 4,000 automated tests that run on every change, so regressions are caught before release.
Audit logging & SIEM export
Security-relevant actions are recorded in an immutable per-organization audit trail that you can export as CSV, JSON, or CEF, and stream to your SIEM (Enterprise).
6. Subprocessors
We use a small set of vetted subprocessors. Each receives only the data it needs to perform its function.
| Subprocessor | Purpose | Data shared |
|---|---|---|
| Anthropic | AI support assistant, executive-summary narratives, and interface translation | Your chat messages and, when you are signed in, a short account summary; aggregate posture figures for summaries you request — never file contents or credentials |
| Resend | Transactional email delivery (account, security and billing email) | Recipient email address and message content |
| PayPal | Subscription billing and payments | Billing identifiers and transaction metadata |
| RunPod | Application compute and the PostgreSQL database | Encrypted application data (metadata + findings) |
| Cloudflare | CDN, WAF, and DDoS protection at the network edge | In-transit request metadata; no data at rest |
7. Contact
Need security documentation, a subprocessor list, or answers for a vendor review? Email [email protected].