Security

Last updated: July 24, 2026

Security and tenant isolation are core to how ProofLoupe is built. This page summarizes our approach.

Per-organization isolation

Each organization's data lives in its own database, with the data handle bound to exactly one tenant and derived from the request hostname — so a routing bug is loud, not a silent cross-tenant leak. Sessions, tokens, and asset URLs are tenant-scoped.

Encryption

Data is encrypted in transit (TLS) and at rest. Secrets are held in a managed secret store, never in source.

Access & auditing

Internal support access to an organization requires an explicit, time-bounded, and audited grant; while it is active, the organization sees an impersonation banner. Operator and support roles are separated by least privilege.

Backups

Each tenant database is backed up independently, so recovery for one organization never touches another.

Responsible disclosure

Found a vulnerability? Please email security@proofloupe.com. We appreciate coordinated disclosure and will work with you on a fix.