Security
Security at Damasol
This page is maintained by Damasol and summarizes the controls and practices currently in place to protect customer data across our products.
Encryption in transit and at rest
TLS for connections and database encryption from major cloud providers protect data end to end.
Access controls and roles
Role-based access, secure sign-in, and row-level security (RLS) policies at the database layer.
Trusted cloud infrastructure
We run on leading cloud providers with clear separation between environments.
Privacy by default
We collect the minimum data required and give you control over access, deletion, and export.
Audit logging
Sensitive events are logged centrally to enable review and investigation.
Incident response
We maintain a documented process to investigate incidents and notify affected customers within legally required timeframes.
Shared responsibility
We are responsible for platform and infrastructure security; you are responsible for protecting your credentials and using the service safely.
Reporting vulnerabilities
If you discover a security issue, please email us directly at hello@damasol.net with clear reproduction details.
This page is an editable disclosure maintained by Damasol and is not an independent certification or audit.
