10110010011101001011001101101110101018200.devFrom Enterprise.Systems
Start free

Trust & Security

8200.dev is built to meet enterprise security requirements. This page describes how we protect your data, what we can and cannot access, and how we operate. We state our posture plainly — and we never claim a certification we do not hold.

1. Security Architecture

  • Encryption at rest

    All sensitive data, including connector credentials and identity-provider certificates, is encrypted at rest with AES-256-GCM.

  • Encryption in transit

    All traffic is served over TLS 1.3 (HTTPS), with HSTS enforced so browsers refuse to connect insecurely.

  • Authentication & MFA

    Sign in with Google, or with an email and password — at least 12 characters, stored only as salted scrypt hashes, with rate-limited sign-in attempts. Two-factor authentication (TOTP plus backup codes) is available to everyone and can be required org-wide; Enterprise adds SAML single sign-on (Okta, Azure AD, Google Workspace, OneLogin) with just-in-time provisioning and assertion replay protection.

  • Role-based access control

    Built-in Owner, Admin, and Viewer roles plus fine-grained custom roles let you grant least-privilege access. Permissions are enforced on every request.

  • Session & network controls

    Configurable session maximum-duration and idle-timeout policies, plus IP allowlisting that restricts access to ranges you trust (Enterprise).

  • Edge protection

    Cloudflare provides a Web Application Firewall and DDoS protection in front of the application, with security headers (CSP, HSTS, frame-deny) on every response.

2. Data Handling

Monitoring is read-only. The platform connects with the narrowest scopes that let it assess your posture, it never needs the contents of your files, and it changes nothing in your sources unless you turn on auto-remediation.

  • Read-only monitoring

    Connectors monitor through read-only scopes. For Google Workspace, the scan runs on drive.metadata.readonly — it can read sharing metadata, not file contents. Write access exists only for auto-remediation: off by default, granted separately per connector, and limited to revoking or reducing access.

  • Metadata and findings only

    We store permission metadata, the access graph, and the findings we derive from it. We do not store, index, or transmit the contents of your documents.

  • Configurable retention

    Operational data follows your retention policy — for example up to 24 months of audit history and a 90-day window for transient data — with a safety floor so nothing is purged accidentally.

  • Self-serve export & deletion

    Owners can export their organization’s data and request account deletion themselves. Deletion runs on a grace window and then removes the data.

3. Compliance

We map our controls and the evidence the product generates to the major frameworks. These are mappings to help your own audit — 8200.dev is not certified against these standards, and we will never claim otherwise.

  • Framework mapping

    Controls and product evidence are mapped to SOC 2, ISO 27001, GDPR, HIPAA, and NIST CSF 2.0. The in-app compliance dashboard tracks all five side by side with gap analysis and an exportable evidence package.

  • Google API Limited Use

    The use of raw or derived user data received from Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements. Workspace data is used only to provide and improve the security features you enable — we never use it to develop, improve, or train generalized AI or machine-learning models, and we never transfer it to third-party AI or ML tools or services for training purposes.

  • Google OAuth verification

    Google approved 8200.dev’s OAuth verification on 2026-08-23 for the three scopes it requests: drive.metadata.readonly for the scan, and admin.directory.user.readonly and admin.directory.user.security for the optional third-party-app audit. Any new scope — including the write scope auto-remediation would need on Google Workspace — requires a new verification before we use it.

4. AI Agent Accountability

The 2026 liability shift holds the company deploying AI accountable for what its agents do. 8200.dev produces the evidence that you governed that access. This supports your compliance posture; it is not legal advice and does not guarantee any outcome.

  • Complete agent inventory

    Agent Guard keeps a live inventory of every AI agent and service account that can reach your data, plus the third-party OAuth grants behind shadow AI — you cannot govern what you cannot see.

  • Immutable access record

    Every access decision and change is recorded in an exportable audit trail (CSV / JSON / CEF / SIEM), so you can reconstruct what an AI agent could reach, and when.

  • Demonstrable governance

    Prevention rules, access enforcement, and a documented risk timeline show active control and response — the evidence behind a defensible AI-governance program.

5. Operational Security

  • Continuous health checks

    Automated health checks run every five minutes across the platform, database, and connectors, opening an incident automatically when something degrades.

  • Public status page

    A public status page publishes uptime history and incident updates so you always know the current state.

  • Automated testing

    The codebase is covered by more than 4,000 automated tests that run on every change, so regressions are caught before release.

  • Audit logging & SIEM export

    Security-relevant actions are recorded in an immutable per-organization audit trail that you can export as CSV, JSON, or CEF, and stream to your SIEM (Enterprise).

6. Subprocessors

We use a small set of vetted subprocessors. Each receives only the data it needs to perform its function.

SubprocessorPurposeData shared
AnthropicAI support assistant, executive-summary narratives, and interface translationYour chat messages and, when you are signed in, a short account summary; aggregate posture figures for summaries you request — never file contents or credentials
ResendTransactional email delivery (account, security and billing email)Recipient email address and message content
PayPalSubscription billing and paymentsBilling identifiers and transaction metadata
RunPodApplication compute and the PostgreSQL databaseEncrypted application data (metadata + findings)
CloudflareCDN, WAF, and DDoS protection at the network edgeIn-transit request metadata; no data at rest

7. Contact

Need security documentation, a subprocessor list, or answers for a vendor review? Email [email protected].