SegAudit
Trust center

Company security

How the company protects its own systems, code and the little customer data it holds.

Some commitments on this page are being put in place before the first paid release. Each item's status is marked.

The company holds no customer firewall data. It does hold source code, signing pipelines, and customer account and billing records. These policies cover them; summaries are below and full policies will be in the security pack.

Policy Summary
Access control Least privilege; access reviewed quarterly
Authentication Multi-factor authentication on every company account, including source control, email and payments
Devices Full-disk encryption, automatic updates and screen lock on every company device
Source code Private repository with a protected main branch; every change by pull request with automated checks
Release signing Release images signed keyless from CI; no signing key is kept on a personal device
Incident response Documented process; customers notified of incidents that affect them without undue delay
Vendor management Vendors limited to the subprocessors list and reviewed yearly
Backup Source and business records backed up off-site

Last updated 2026-10-04.