Skip to content
Security & compliance

Your data, isolated and accounted for

Multi-tenant isolation from the first line of code, two-factor authentication with backup codes, and an audit log that records the old and new value of every change.

Encryption in transit and at rest

  • TLS for all data in transit
  • Encryption at rest via our managed database platform
  • Managed, encrypted database backups
  • Secrets held as managed environment config, never in source

Access control

  • TOTP two-factor authentication
  • One-time backup codes for lost devices
  • Lockout after repeated failed 2FA attempts
  • Custom roles with granular permissions

Tenant isolation

  • Every row scoped to an organisation
  • Authorisation enforced on the server, not in the UI
  • Organisation and project access checked on every request
  • Project-level roles and permissions

Auditability

  • Organisation, project and admin changes logged with actor and timestamp
  • Old → new values recorded on every change
  • Audit log browsable in organisation settings
  • Active session list with remote revocation

Infrastructure

  • Managed PostgreSQL with point-in-time recovery
  • Automated daily backups, 30-day retention
  • Rate limiting on every authentication endpoint
  • CSRF protection and strict content security policy

Data ownership

  • Issue export in CSV, JSON, PDF and release-notes format
  • Export available on every plan, at any time
  • Deletion on request within 30 days
  • No lock-in — your data leaves in an open format
Operating practice

How we work day to day

Security posture is a habit, not a certificate on a wall.

Vulnerability reporting
Email hello@sprintguage.com — we acknowledge within one business day.
Dependency scanning
Automated on every pull request and daily on the default branch.
Access reviews
Employee access to production is least-privilege and reviewed quarterly.
Incident response
Documented runbook with customer notification inside 72 hours.
Backups
Tested restores on a monthly cadence, not just scheduled dumps.
Sub-processors
List available on request, with 30 days' notice before any change.

Need a security questionnaire completed?

Send it over and we will turn it around, usually within three business days.

Contact security

Move your team over this week

Create a project, pick your statuses, and have your first sprint running the same afternoon. Free for up to 10 users.

No credit card required · Cancel any time · Export your data whenever you like