Security

Security at Damasol

This page is maintained by Damasol and summarizes the controls and practices currently in place to protect customer data across our products.

Encryption in transit and at rest

TLS for connections and database encryption from major cloud providers protect data end to end.

Access controls and roles

Role-based access, secure sign-in, and row-level security (RLS) policies at the database layer.

Trusted cloud infrastructure

We run on leading cloud providers with clear separation between environments.

Privacy by default

We collect the minimum data required and give you control over access, deletion, and export.

Audit logging

Sensitive events are logged centrally to enable review and investigation.

Incident response

We maintain a documented process to investigate incidents and notify affected customers within legally required timeframes.

Shared responsibility

We are responsible for platform and infrastructure security; you are responsible for protecting your credentials and using the service safely.

Reporting vulnerabilities

If you discover a security issue, please email us directly at hello@damasol.net with clear reproduction details.

This page is an editable disclosure maintained by Damasol and is not an independent certification or audit.